Overview
The Apache web server mod_proxy_ftp module contains a cross-site scripting (XSS) vulnerability.
Description
The Apache mod_proxy_ftp module allows the Apache web server to act as a proxy for FTP sites. Filename globbing is the process of using wildcards to match filenames. The mod_proxy_ftp module contains an XSS vulnerability that occurs because the module does not properly filter globbed characters in FTP URIs. |
Impact
A remote attacker may be able to execute arbitrary Javascript in the context of a site being proxied by the Apache server. |
Solution
Upgrade Apache has released updates to address this issue. These updates are available on the Apache SVN server: |
Workarounds
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
Thanks to Rapid7 and Apache for information that was used in this report.
This document was written by Ryan Giobbi.
Other Information
CVE IDs: | CVE-2008-2939 |
Severity Metric: | 2.70 |
Date Public: | 2008-08-06 |
Date First Published: | 2008-08-08 |
Date Last Updated: | 2008-08-08 19:17 UTC |
Document Revision: | 17 |