The default configuration of the apache2 package in Debian GNU/Linux squeeze before 2.2.16-6+squeeze7, wheezy before 2.2.22-4, and sid before 2.2.22-4, when mod_php or mod_rivet is used, provides example scripts under the doc/ URI, which might allow local users to conduct cross-site scripting (XSS) attacks, gain privileges, or obtain sensitive information via vectors involving localhost HTTP requests to the Apache HTTP Server.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2452-1 | apache2 security update |
EUVD |
EUVD-2012-0252 | The default configuration of the apache2 package in Debian GNU/Linux squeeze before 2.2.16-6+squeeze7, wheezy before 2.2.22-4, and sid before 2.2.22-4, when mod_php or mod_rivet is used, provides example scripts under the doc/ URI, which might allow local users to conduct cross-site scripting (XSS) attacks, gain privileges, or obtain sensitive information via vectors involving localhost HTTP requests to the Apache HTTP Server. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 27 Aug 2025 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Debian debian Linux
|
|
| CPEs | cpe:2.3:a:debian:apache2:*:squeeze6:*:*:*:*:*:* cpe:2.3:a:debian:apache2:*:wheezy:*:*:*:*:*:* |
cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:* cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* |
| Vendors & Products |
Debian apache2
|
Debian debian Linux
|
Status: PUBLISHED
Assigner: debian
Published:
Updated: 2024-08-06T18:16:19.970Z
Reserved: 2011-12-14T00:00:00
Link: CVE-2012-0216
No data.
Status : Analyzed
Published: 2012-04-22T18:55:03.140
Modified: 2025-08-27T11:17:02.550
Link: CVE-2012-0216
No data.
OpenCVE Enrichment
No data.
Debian DSA
EUVD