TROYANOSYVIRUS
Retour aux CVEs

CVE-2008-2939

N/A

Description

Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web script or HTML via a wildcard in the last directory component in the pathname in an FTP URI.

Details CVE

Score CVSS v3.1N/A
Publie8/6/2008
Derniere modification4/23/2026
Sourcenvd
Observations honeypot0

Produits affectes

apache:http_serverapple:mac_os_xcanonical:ubuntu_linuxopensuse:opensuse

Faiblesses (CWE)

CWE-79

References

http://marc.info/?l=bugtraq&m=123376588623823&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://marc.info/?l=bugtraq&m=125631037611762&w=2(af854a3a-2127-422b-91ae-364da2661108)
http://rhn.redhat.com/errata/RHSA-2008-0967.html(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/31384(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/31673(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/32685(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/32838(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/33156(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/33797(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/34219(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/35074(af854a3a-2127-422b-91ae-364da2661108)
http://support.apple.com/kb/HT3549(af854a3a-2127-422b-91ae-364da2661108)
http://svn.apache.org/viewvc?view=rev&revision=682868(af854a3a-2127-422b-91ae-364da2661108)
http://svn.apache.org/viewvc?view=rev&revision=682870(af854a3a-2127-422b-91ae-364da2661108)
http://svn.apache.org/viewvc?view=rev&revision=682871(af854a3a-2127-422b-91ae-364da2661108)
http://wiki.rpath.com/Advisories:rPSA-2008-0327(af854a3a-2127-422b-91ae-364da2661108)
http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0328(af854a3a-2127-422b-91ae-364da2661108)
http://www-1.ibm.com/support/docview.wss?uid=swg1PK70197(af854a3a-2127-422b-91ae-364da2661108)
http://www-1.ibm.com/support/docview.wss?uid=swg1PK70937(af854a3a-2127-422b-91ae-364da2661108)
http://www.kb.cert.org/vuls/id/663763(af854a3a-2127-422b-91ae-364da2661108)
http://www.rapid7.com/advisories/R7-0033(af854a3a-2127-422b-91ae-364da2661108)
http://www.redhat.com/support/errata/RHSA-2008-0966.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/30560(af854a3a-2127-422b-91ae-364da2661108)
http://www.securitytracker.com/id?1020635(af854a3a-2127-422b-91ae-364da2661108)
http://www.ubuntu.com/usn/USN-731-1(af854a3a-2127-422b-91ae-364da2661108)
http://www.us-cert.gov/cas/techalerts/TA09-133A.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.vupen.com/english/advisories/2008/2315(af854a3a-2127-422b-91ae-364da2661108)
http://www.vupen.com/english/advisories/2008/2461(af854a3a-2127-422b-91ae-364da2661108)
http://www.vupen.com/english/advisories/2009/0320(af854a3a-2127-422b-91ae-364da2661108)
http://www.vupen.com/english/advisories/2009/1297(af854a3a-2127-422b-91ae-364da2661108)

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.