The default configuration of the apache2 package in Debian GNU/Linux squeeze before 2.2.16-6+squeeze7, wheezy before 2.2.22-4, and sid before 2.2.22-4, when mod_php or mod_rivet is used, provides example scripts under the doc/ URI, which might allow local users to conduct cross-site scripting (XSS) attacks, gain privileges, or obtain sensitive information via vectors involving localhost HTTP requests to the Apache HTTP Server.
Advisories
Source ID Title
Debian DSA Debian DSA DSA-2452-1 apache2 security update
EUVD EUVD EUVD-2012-0252 The default configuration of the apache2 package in Debian GNU/Linux squeeze before 2.2.16-6+squeeze7, wheezy before 2.2.22-4, and sid before 2.2.22-4, when mod_php or mod_rivet is used, provides example scripts under the doc/ URI, which might allow local users to conduct cross-site scripting (XSS) attacks, gain privileges, or obtain sensitive information via vectors involving localhost HTTP requests to the Apache HTTP Server.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 27 Aug 2025 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Debian debian Linux
CPEs cpe:2.3:a:debian:apache2:*:sid:*:*:*:*:*:*
cpe:2.3:a:debian:apache2:*:squeeze6:*:*:*:*:*:*
cpe:2.3:a:debian:apache2:*:wheezy:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
Vendors & Products Debian apache2
Debian debian Linux

cve-icon MITRE

Status: PUBLISHED

Assigner: debian

Published:

Updated: 2024-08-06T18:16:19.970Z

Reserved: 2011-12-14T00:00:00

Link: CVE-2012-0216

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2012-04-22T18:55:03.140

Modified: 2025-08-27T11:17:02.550

Link: CVE-2012-0216

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.