Lucene search

K
f5F5F5:K17267
HistorySep 15, 2015 - 12:00 a.m.

K17267 : XSS vulnerability in Apache CVE-2002-0840

2015-09-1500:00:00
my.f5.com
56

5.5 Medium

AI Score

Confidence

High

0.971 High

EPSS

Percentile

99.8%

Security Advisory Description

Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is “Off” and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors via the Host: header, a different vulnerability than CAN-2002-1157. (CVE-2002-0840)

Impact

There is no impact; F5 products are not affected by this vulnerability.

5.5 Medium

AI Score

Confidence

High

0.971 High

EPSS

Percentile

99.8%