CVE-2007-6203

CVSS V2 Medium 4.3 CVSS V3 None
Description
Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "413 Request Entity Too Large" error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated via an HTTP request containing an invalid Content-length value, a similar issue to CVE-2006-3918.
Overview
  • CVE ID
  • CVE-2007-6203
  • Assigner
  • cve@mitre.org
  • Vulnerability Status
  • Modified
  • Published Version
  • 2007-12-03T22:46:00
  • Last Modified Date
  • 2018-10-15T21:50:58
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:apache:http_server:2.0.46:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.47:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.48:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.49:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.50:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.51:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.52:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.53:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.54:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.55:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.57:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.58:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.0.59:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.1.1:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.1.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.1.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.1.4:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.1.5:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.1.6:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.1.7:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.1.8:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.2.0:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.2.2:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.2.3:*:*:*:*:*:*:* 1 OR
cpe:2.3:a:apache:http_server:2.2.4:*:*:*:*:*:*:* 1 OR
CVSS Version 2
  • Version
  • 2.0
  • Vector String
  • AV:N/AC:M/Au:N/C:N/I:P/A:N
  • Access Vector
  • NETWORK
  • Access Compatibility
  • MEDIUM
  • Authentication
  • NONE
  • Confidentiality Impact
  • NONE
  • Integrity Impact
  • PARTIAL
  • Availability Impact
  • NONE
  • Base Score
  • 4.3
  • Severity
  • MEDIUM
  • Exploitability Score
  • 8.6
  • Impact Score
  • 2.9
References
Reference URL Reference Tags
http://procheckup.com/Vulnerability_PR07-37.php Exploit
http://www.securityfocus.com/bid/26663 Exploit
http://secunia.com/advisories/27906 Vendor Advisory
http://www.securitytracker.com/id?1019030
http://www-1.ibm.com/support/docview.wss?uid=swg1PK57952
http://secunia.com/advisories/28196 Vendor Advisory
http://security.gentoo.org/glsa/glsa-200803-19.xml
http://secunia.com/advisories/29348 Vendor Advisory
http://docs.info.apple.com/article.html?artnum=307562
http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html
http://secunia.com/advisories/29420 Vendor Advisory
http://securityreason.com/securityalert/3411
http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00004.html
http://secunia.com/advisories/29640 Vendor Advisory
http://www-1.ibm.com/support/docview.wss?uid=swg24019245
http://secunia.com/advisories/30356 Vendor Advisory
http://secunia.com/advisories/30732 Vendor Advisory
http://www.fujitsu.com/global/support/software/security/products-f/interstage-200807e.html
http://secunia.com/advisories/33105 Vendor Advisory
http://www.ubuntu.com/usn/USN-731-1
http://secunia.com/advisories/34219 Vendor Advisory
http://marc.info/?l=bugtraq&m=125631037611762&w=2
http://marc.info/?l=bugtraq&m=129190899612998&w=2
http://www.vupen.com/english/advisories/2007/4301
http://www.vupen.com/english/advisories/2007/4060
http://www.vupen.com/english/advisories/2008/1623/references
http://www.vupen.com/english/advisories/2008/0924/references
http://www.vupen.com/english/advisories/2008/1875/references
https://exchange.xforce.ibmcloud.com/vulnerabilities/38800
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12166
http://www.securityfocus.com/archive/1/484410/100/0/threaded
History
Created Old Value New Value Data Type Notes
2022-05-10 18:19:31 Added to TrackCVE