Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23184
HistoryApr 10, 2020 - 12:18 a.m.

Cross-Site Scripting (XSS)

2020-04-1000:18:54
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

0.011 Low

EPSS

Percentile

84.4%

httpd is vulnerable to cross-site scripting. A flaw was found in the mod_autoindex module. On sites where directory listings are used, and the AddDefaultCharset directive has been removed from the configuration, a cross-site-scripting attack may be possible against browsers which do not correctly derive the response character set following the rules in RFC 2616.

References