Back

MEDIUM

mod_autoindex XSS

Published Sep 14, 2007

Description

Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is not defined, allows remote attackers to inject arbitrary web script or HTML via the P parameter using the UTF-7 charset. NOTE: it could be argued that this issue is due to a design limitation of browsers that attempt to perform automatic content type detection.

Affected products

Remediation

Red Hat statement

This is actually a flaw in browsers that do not derive the response character set as required by RFC 2616. This does not affect the default configuration of Apache httpd in Red Hat products and will only affect customers who have removed the "AddDefaultCharset" directive and are using directory indexes. The Red Hat Product Security has rated this issue as having low security impact, a future update may address this flaw.

Metrics

References (46)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 14, 2007
Updated Jan 17, 2025
Reserved Aug 21, 2007
CISA Vulnrichment
Updated Jan 5, 2024
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Sep 13, 2007