Lucene search

K
f5F5F5:K15901
HistoryJun 08, 2015 - 12:00 a.m.

K15901 : Apache HTTP server vulnerability CVE-2012-2687

2015-06-0800:00:00
my.f5.com
14

AI Score

5.6

Confidence

High

EPSS

0.007

Percentile

80.0%

Security Advisory Description

Multiple cross-site scripting (XSS) vulnerabilities in the make_variant_list function in mod_negotiation.c in the mod_negotiation module in the Apache HTTP Server 2.4.x before 2.4.3, when the MultiViews option is enabled, allow remote attackers to inject arbitrary web script or HTML via a crafted filename that is not properly handled during construction of a variant list. (CVE-2012-2687)

Impact

An attacker may be able to inject arbitrary web script or HTML.