Back

MEDIUM

httpd: XSS via UTF-7 encoded urls on the 403 Forbidden error page

Published May 13, 2008

Description

Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded URLs that are not properly handled when displaying the 403 Forbidden error page.

Affected products

Remediation

Red Hat statement

This is actually a flaw in browsers that do not derive the response character set as required by RFC 2616. This does not affect the default configuration of Apache httpd in Red Hat products and will only affect customers who have removed the "AddDefaultCharset" directive. https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2008-2168

Metrics

References (19)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 13, 2008
Updated Aug 7, 2024
Reserved May 13, 2008
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date May 8, 2008