| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.902830 |
| Category: | Web Servers |
| Title: | Apache HTTP Server 'httpOnly' Cookie Information Disclosure Vulnerability |
| Summary: | Check Apache httpd web server is vulnerable to Cookie Disclosure |
| Description: | Overview: This host is running Apache HTTP Server and is prone to cookie information disclosure vulnerability. Vulnerability Insight: The flaw is due to an error within the default error response for status code 400 when no custom ErrorDocument is configured, which can be exploited to expose 'httpOnly' cookies. Impact: Successful exploitation will allow attackers to obtain sensitive information that may aid in further attacks. Impact Level: Application Affected Software/OS: Apache HTTP Server versions 2.2.0 through 2.2.21 Fix: Upgrade to Apache HTTP Server version 2.2.22 or later, For updates refer to http://httpd.apache.org/ References: http://osvdb.org/78556 http://secunia.com/advisories/47779 http://www.exploit-db.com/exploits/18442 http://rhn.redhat.com/errata/RHSA-2012-0128.html http://httpd.apache.org/security/vulnerabilities_22.html http://svn.apache.org/viewvc?view=revision&revision=1235454 http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00026.html |
| Cross-Ref: |
BugTraq ID: 51706 Common Vulnerability Exposure (CVE) ID: CVE-2012-0053 http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html HPdes Security Advisory: HPSBMU02786 http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03360041 HPdes Security Advisory: SSRT100877 RedHat Security Advisories: RHSA-2012:0128 http://rhn.redhat.com/errata/RHSA-2012-0128.html SuSE Security Announcement: openSUSE-SU-2012:0314 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00026.html http://www.securityfocus.com/bid/51706 http://secunia.com/advisories/48551 |
| Copyright | Copyright (C) 2012 SecPod |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|