http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected back in an error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated using a Flash SWF file.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1167-1 | New apache packages fix several vulnerabilities |
Ubuntu USN |
USN-575-1 | Apache vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T18:48:39.410Z
Reserved: 2006-07-27T00:00:00
Link: CVE-2006-3918
No data.
Status : Deferred
Published: 2006-07-28T00:04:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2006-3918
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
Ubuntu USN