Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.100130
Category:Web application abuses
Title:Apache mod_perl 'Apache::Status' and 'Apache2::Status' XSS Vulnerability
Summary:According to its version number, the remote version of the; Apache mod_perl module is prone to a cross-site scripting (XSS) vulnerability because it fails to; sufficiently sanitize user-supplied data.
Description:Summary:
According to its version number, the remote version of the
Apache mod_perl module is prone to a cross-site scripting (XSS) vulnerability because it fails to
sufficiently sanitize user-supplied data.

Vulnerability Impact:
An attacker may leverage this issue to execute arbitrary script
code in the browser of an unsuspecting user in the context of the affected site. This may allow
the attacker to steal cookie-based authentication credentials and to launch other attacks.

Solution:
The vendor has released a fix through the SVN repository.
Please see the references for more information.

CVSS Score:
2.6

CVSS Vector:
AV:N/AC:H/Au:N/C:N/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2009-0796
1021508
http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021508.1-1
1021709
http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021709.1-1
1021988
http://www.securitytracker.com/id?1021988
20090415 XSS with mod_perl perl_status utility
http://www.securityfocus.com/archive/1/502709/100/0/threaded
34383
http://www.securityfocus.com/bid/34383
34597
http://secunia.com/advisories/34597
ADV-2009-0943
http://www.vupen.com/english/advisories/2009/0943
APPLE-SA-2010-11-10-1
http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html
MDVSA-2009:091
http://www.mandriva.com/security/advisories?name=MDVSA-2009:091
[modperl-cvs] 20090401 svn commit: r761081 - in /perl/modperl/branches/1.x: Changes lib/Apache/Status.pm
http://www.gossamer-threads.com/lists/modperl/modperl-cvs/99477#99477
[modperl] 20090401 [SECURITY] [CVE-2009-0796] Vulnerability found in Apache::Status and Apache2::Status
http://www.gossamer-threads.com/lists/modperl/modperl/99475#99475
http://support.apple.com/kb/HT4435
http://svn.apache.org/viewvc/perl/modperl/branches/1.x/lib/Apache/Status.pm?r1=177851&r2=761081&pathrev=761081&diff_format=h
http://svn.apache.org/viewvc?view=rev&revision=761081
https://bugzilla.redhat.com/show_bug.cgi?id=494402
https://launchpad.net/bugs/cve/2009-0796
oval:org.mitre.oval:def:8488
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8488
CopyrightCopyright (C) 2009 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.