httpd: mod_proxy_ftp globbing XSS
Published Aug 6, 2008
4.3
MEDIUMCVSS 2.0
EPSS 38.95%
Description
Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web script or HTML via a wildcard in the last directory component in the pathname in an FTP URI.
Affected products
No data.
Configuration 1
- ≤ 2.0.63
- ≥ 2.2.0 · ≤ 2.2.9
Configuration 2
- ≤ 10.5.6
- 6.06
- 7.10
- 8.04
- 10.2
- 10.3
- 11.0
No data.
Red Hat Certificate System 7.3
ant-0:1.6.5-1jpp_1rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
avalon-logkit-0:1.2-2jpp_4rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
axis-0:1.2.1-1jpp_3rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
classpathx-jaf-0:1.0-2jpp_6rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
classpathx-mail-0:1.1.1-2jpp_8rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
geronimo-specs-0:1.0-0.M4.1jpp_10rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
jakarta-commons-modeler-0:2.0-3jpp_2rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
log4j-0:1.2.12-1jpp_1rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
mx4j-1:3.0.1-1jpp_4rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
pcsc-lite-0:1.3.3-3.el4
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
rhpki-ca-0:7.3.0-20.el4
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
rhpki-java-tools-0:7.3.0-10.el4
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
rhpki-kra-0:7.3.0-14.el4
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
rhpki-manage-0:7.3.0-19.el4
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
rhpki-native-tools-0:7.3.0-6.el4
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
rhpki-ocsp-0:7.3.0-13.el4
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
rhpki-tks-0:7.3.0-13.el4
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
tomcat5-0:5.5.23-0jpp_4rh.16
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
xerces-j2-0:2.7.1-1jpp_1rh
Fixed · RHSA-2010:0602
Red Hat Certificate System 7.3
xml-commons-0:1.3.02-2jpp_1rh
Fixed · RHSA-2010:0602
Red Hat Enterprise Linux 3
httpd-0:2.0.46-71.ent
Fixed · RHSA-2008:0967
Red Hat Enterprise Linux 4
httpd-0:2.0.52-41.ent.2
Fixed · RHSA-2008:0967
Red Hat Enterprise Linux 5
httpd-0:2.2.3-11.el5_2.4
Fixed · RHSA-2008:0967
Red Hat Directory Server 8
httpd
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Certificate System 7.3 | ant-0:1.6.5-1jpp_1rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | avalon-logkit-0:1.2-2jpp_4rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | axis-0:1.2.1-1jpp_3rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | classpathx-jaf-0:1.0-2jpp_6rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | classpathx-mail-0:1.1.1-2jpp_8rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | geronimo-specs-0:1.0-0.M4.1jpp_10rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | jakarta-commons-modeler-0:2.0-3jpp_2rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | log4j-0:1.2.12-1jpp_1rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | mx4j-1:3.0.1-1jpp_4rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | pcsc-lite-0:1.3.3-3.el4 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | rhpki-ca-0:7.3.0-20.el4 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | rhpki-java-tools-0:7.3.0-10.el4 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | rhpki-kra-0:7.3.0-14.el4 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | rhpki-manage-0:7.3.0-19.el4 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | rhpki-native-tools-0:7.3.0-6.el4 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | rhpki-ocsp-0:7.3.0-13.el4 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | rhpki-tks-0:7.3.0-13.el4 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | tomcat5-0:5.5.23-0jpp_4rh.16 | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | xerces-j2-0:2.7.1-1jpp_1rh | Fixed | RHSA-2010:0602 |
| Red Hat Certificate System 7.3 | xml-commons-0:1.3.02-2jpp_1rh | Fixed | RHSA-2010:0602 |
| Red Hat Enterprise Linux 3 | httpd-0:2.0.46-71.ent | Fixed | RHSA-2008:0967 |
| Red Hat Enterprise Linux 4 | httpd-0:2.0.52-41.ent.2 | Fixed | RHSA-2008:0967 |
| Red Hat Enterprise Linux 5 | httpd-0:2.2.3-11.el5_2.4 | Fixed | RHSA-2008:0967 |
| Red Hat Directory Server 8 | httpd | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (56 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 38.95% (0.38953) | 98.55th | v5 (v2026.06.15) |
| Jun 15, 2026 | 38.95% (0.38953) | 98.40th | v5 (v2026.06.15) |
| Apr 7, 2026 | 64.56% (0.64560) | 98.45th | v4 (v2025.03.14) |
| Mar 4, 2026 | 71.25% (0.71247) | 98.69th | v4 (v2025.03.14) |
| Mar 1, 2026 | 33.52% (0.33521) | 96.86th | v4 (v2025.03.14) |
| Feb 18, 2026 | 71.25% (0.71247) | 98.68th | v4 (v2025.03.14) |
| Feb 4, 2026 | 76.09% (0.76085) | 98.89th | v4 (v2025.03.14) |
| Feb 1, 2026 | 39.88% (0.39878) | 97.23th | v4 (v2025.03.14) |
| Jan 4, 2026 | 76.09% (0.76085) | 98.88th | v4 (v2025.03.14) |
| Jan 1, 2026 | 39.88% (0.39878) | 97.21th | v4 (v2025.03.14) |
| Dec 28, 2025 | 76.09% (0.76085) | 98.87th | v4 (v2025.03.14) |
| Dec 27, 2025 | 78.52% (0.78524) | 98.99th | v4 (v2025.03.14) |
| Dec 4, 2025 | 76.09% (0.76085) | 98.86th | v4 (v2025.03.14) |
| Dec 1, 2025 | 39.88% (0.39878) | 97.17th | v4 (v2025.03.14) |
| Nov 4, 2025 | 64.83% (0.64828) | 98.38th | v4 (v2025.03.14) |
| Nov 1, 2025 | 33.64% (0.33636) | 96.76th | v4 (v2025.03.14) |
| Oct 28, 2025 | 64.83% (0.64828) | 98.37th | v4 (v2025.03.14) |
| Oct 27, 2025 | 68.33% (0.68325) | 98.54th | v4 (v2025.03.14) |
| Oct 22, 2025 | 64.83% (0.64828) | 98.36th | v4 (v2025.03.14) |
| Oct 4, 2025 | 67.24% (0.67242) | 98.50th | v4 (v2025.03.14) |
| Oct 1, 2025 | 36.53% (0.36531) | 97.02th | v4 (v2025.03.14) |
| Sep 6, 2025 | 68.33% (0.68325) | 98.55th | v4 (v2025.03.14) |
| Sep 1, 2025 | 34.35% (0.34348) | 96.87th | v4 (v2025.03.14) |
| Aug 4, 2025 | 68.33% (0.68325) | 98.53th | v4 (v2025.03.14) |
| Aug 1, 2025 | 40.75% (0.40747) | 97.27th | v4 (v2025.03.14) |
| Jul 30, 2025 | 68.33% (0.68325) | 98.53th | v4 (v2025.03.14) |
| Jul 4, 2025 | 64.83% (0.64828) | 98.35th | v4 (v2025.03.14) |
| Jul 1, 2025 | 40.00% (0.39999) | 97.18th | v4 (v2025.03.14) |
| Jun 4, 2025 | 64.83% (0.64828) | 98.34th | v4 (v2025.03.14) |
| Jun 1, 2025 | 40.00% (0.39999) | 97.16th | v4 (v2025.03.14) |
| May 4, 2025 | 64.83% (0.64828) | 98.33th | v4 (v2025.03.14) |
| May 1, 2025 | 40.00% (0.39999) | 97.13th | v4 (v2025.03.14) |
| Mar 30, 2025 | 65.01% (0.65014) | 98.34th | v4 (v2025.03.14) |
| Mar 29, 2025 | 59.36% (0.59356) | 97.47th | v4 (v2025.03.14) |
| Mar 17, 2025 | 65.01% (0.65014) | 98.32th | v4 (v2025.03.14) |
| Dec 17, 2024 | 9.92% (0.09922) | 94.86th | v3 (v2023.03.01) |
| Dec 12, 2024 | 11.43% (0.11431) | 95.48th | v3 (v2023.03.01) |
| Aug 12, 2024 | 12.17% (0.12175) | 95.47th | v3 (v2023.03.01) |
| Apr 27, 2024 | 7.17% (0.07174) | 93.94th | v3 (v2023.03.01) |
| Feb 15, 2024 | 5.37% (0.05366) | 92.82th | v3 (v2023.03.01) |
| Jan 20, 2024 | 7.00% (0.07001) | 93.30th | v3 (v2023.03.01) |
| Jan 10, 2024 | 8.26% (0.08256) | 93.76th | v3 (v2023.03.01) |
| Dec 4, 2023 | 5.17% (0.05167) | 92.12th | v3 (v2023.03.01) |
| Oct 31, 2023 | 5.49% (0.05490) | 92.36th | v3 (v2023.03.01) |
| Sep 26, 2023 | 6.62% (0.06619) | 92.95th | v3 (v2023.03.01) |
| Aug 20, 2023 | 11.27% (0.11267) | 94.46th | v3 (v2023.03.01) |
| Jul 14, 2023 | 12.48% (0.12477) | 94.67th | v3 (v2023.03.01) |
| Jun 6, 2023 | 14.13% (0.14134) | 94.87th | v3 (v2023.03.01) |
| Apr 27, 2023 | 9.15% (0.09153) | 93.70th | v3 (v2023.03.01) |
| Mar 17, 2023 | 6.86% (0.06855) | 92.78th | v3 (v2023.03.01) |
| Mar 7, 2023 | 10.02% (0.10020) | 93.91th | v3 (v2023.03.01) |
| Mar 6, 2023 | 7.34% (0.07344) | 92.59th | v2 (v2022.01.01) |
| Feb 13, 2023 | 7.34% (0.07344) | 92.29th | v2 (v2022.01.01) |
| Feb 3, 2023 | 10.86% (0.10861) | 94.53th | v2 (v2022.01.01) |
| Apr 1, 2022 | 7.34% (0.07344) | 91.87th | v2 (v2022.01.01) |
| Feb 4, 2022 | 7.34% (0.07344) | 80.64th | v2 (v2022.01.01) |
References (66)
- http://lists.apple.com/archives/security-announce/2009/May/msg00002.html vendor-advisoryx_refsource_APPLEMailing List
- http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00000.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- http://marc.info/?l=bugtraq&m=123376588623823&w=2 vendor-advisoryx_refsource_HPThird Party Advisory
- http://marc.info/?l=bugtraq&m=125631037611762&w=2 vendor-advisoryx_refsource_HPThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2008-0967.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://secunia.com/advisories/31384 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/31673 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/32685 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/32838 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/33156 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/33797 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/34219 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/35074 third-party-advisoryx_refsource_SECUNIABroken Link
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-247666-1 vendor-advisoryx_refsource_SUNALERTBroken Link
- http://support.apple.com/kb/HT3549 x_refsource_CONFIRMThird Party Advisory
- http://svn.apache.org/viewvc?view=rev&revision=682868 x_refsource_CONFIRMThird Party Advisory
- http://svn.apache.org/viewvc?view=rev&revision=682870 x_refsource_CONFIRMThird Party Advisory
- http://svn.apache.org/viewvc?view=rev&revision=682871 x_refsource_CONFIRMThird Party Advisory
- http://wiki.rpath.com/Advisories:rPSA-2008-0327 x_refsource_CONFIRMBroken Link
- http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0328 x_refsource_CONFIRMBroken Link
- http://www-1.ibm.com/support/docview.wss?uid=swg1PK70197 vendor-advisoryx_refsource_AIXAPARThird Party Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg1PK70937 vendor-advisoryx_refsource_AIXAPARThird Party Advisory
- http://www.kb.cert.org/vuls/id/663763 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:194 vendor-advisoryx_refsource_MANDRIVABroken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:195 vendor-advisoryx_refsource_MANDRIVABroken Link
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:124 vendor-advisoryx_refsource_MANDRIVABroken Link
- http://www.rapid7.com/advisories/R7-0033 x_refsource_MISCBroken Link
- http://www.redhat.com/support/errata/RHSA-2008-0966.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.securityfocus.com/archive/1/495180/100/0/threaded mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/archive/1/498566/100/0/threaded mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/archive/1/498567/100/0/threaded mailing-listx_refsource_BUGTRAQThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/30560 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id?1020635 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- http://www.ubuntu.com/usn/USN-731-1 vendor-advisoryx_refsource_UBUNTUThird Party AdvisoryVDB Entry
- http://www.us-cert.gov/cas/techalerts/TA09-133A.html third-party-advisoryx_refsource_CERTThird Party AdvisoryUS Government Resource
- http://www.vupen.com/english/advisories/2008/2315 vdb-entryx_refsource_VUPENPermissions Required
- http://www.vupen.com/english/advisories/2008/2461 vdb-entryx_refsource_VUPENPermissions Required
- http://www.vupen.com/english/advisories/2009/0320 vdb-entryx_refsource_VUPENPermissions Required
- http://www.vupen.com/english/advisories/2009/1297 vdb-entryx_refsource_VUPENPermissions Required
- https://access.redhat.com/security/cve/CVE-2008-2939 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=458250 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44223 vdb-entryx_refsource_XFVDB Entry
- https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTThird Party Advisory
- https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTThird Party Advisory
- https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTThird Party Advisory
- https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTThird Party Advisory
- https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTThird Party Advisory
- https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTThird Party Advisory
- https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTThird Party Advisory
- https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTThird Party Advisory
- https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTThird Party Advisory
- https://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTThird Party Advisory
- https://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTThird Party Advisory
- https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTThird Party Advisory
- https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTThird Party Advisory
- https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTThird Party Advisory
- https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTThird Party Advisory
- https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTThird Party Advisory
- https://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTThird Party Advisory
- https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTThird Party Advisory
- https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTThird Party Advisory
- https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E mailing-listx_refsource_MLISTThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2008-2939
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11316 vdb-entrysignaturex_refsource_OVALBroken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7716 vdb-entrysignaturex_refsource_OVALBroken Link
- https://www.cve.org/CVERecord?id=CVE-2008-2939
Change history (0)
No recorded changes yet.