Cross-site scripting vulnerability in the mod_ssl Apache module 2.8.9 and earlier, when UseCanonicalName is off and wildcard DNS is enabled, allows remote attackers to execute script as other web site visitors, via the server name in an HTTPS response on the SSL port, which is used in a self-referencing URL, a different vulnerability than CAN-2002-0840.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2004-09-01T04:00:00
Updated: 2024-08-08T03:19:27.695Z
Reserved: 2002-09-26T00:00:00
Link: CVE-2002-1157
Vulnrichment
No data.
NVD
Status : Modified
Published: 2002-11-04T05:00:00.000
Modified: 2024-11-20T23:40:43.400
Link: CVE-2002-1157
Redhat