Apache Web Server默认错误页面跨站脚本漏洞

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1107023 漏洞类型 输入验证
发布时间 2002-10-02 更新时间 2005-10-12
CVE编号 CVE-2002-0840 CNNVD-ID CNNVD-200210-265
漏洞平台 Multiple CVSS评分 6.8
|漏洞来源
https://www.exploit-db.com/exploits/21885
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200210-265
|漏洞详情
Apache是一款广泛使用的开放源代码WEB服务程序。Apache的对默认错误页面的处理存在问题,攻击者可以利用此漏洞执行跨站脚本攻击。起因是没有正确的过滤SSI错误页面的恶意HTML代码。攻击者可以利用这个漏洞在访问恶意链接的客户端执行HTML和脚本代码,导致控制Web内容或窃取基于cookie的认证凭证。请注意仅在UseCanonicalName设置为Off且服务器运行在使用了通配符DNS的域中的情况下才可能利用这个漏洞。
|漏洞EXP
source: http://www.securityfocus.com/bid/5847/info

Apache is reported to be vulnerable to cross site scripting attacks. This vulnerability is due to the SSI error pages of the webserver not being properly sanitized of malicious HTML code.

Attacker-supplied HTML and script code may be executed on a web client visiting the malicious link in the context of the webserver.

Attacks of this nature may make it possible for attackers to manipulate web content or to steal cookie-based authentication credentials. It may be possible to take arbitrary actions as the victim user.

http://%3CIMG%20SRC%3D%22%22%20ONERROR%3D%22alert%28document%2Ecookie%29%22
%3E.apachesite.org/raise_404
|参考资料

来源:US-CERTVulnerabilityNote:VU#240329
名称:VU#240329
链接:http://www.kb.cert.org/vuls/id/240329
来源:BUGTRAQ
名称:20021002Apache2Cross-SiteScripting
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=103357160425708&w=2
来源:XF
名称:apache-http-host-xss(10241)
链接:http://xforce.iss.net/xforce/xfdb/10241
来源:www.apacheweek.com
链接:http://www.apacheweek.com/issues/02-10-04
来源:BID
名称:5847
链接:http://www.securityfocus.com/bid/5847
来源:REDHAT
名称:RHSA-2003:106
链接:http://www.redhat.com/support/errata/RHSA-2003-106.html
来源:REDHAT
名称:RHSA-2002:251
链接:http://www.redhat.com/support/errata/RHSA-2002-251.html
来源:REDHAT
名称:RHSA-2002:248
链接:http://www.redhat.com/support/errata/RHSA-2002-248.html
来源:REDHAT
名称:RHSA-2002:244
链接:http://www.redhat.com/support/errata/RHSA-2002-244.html
来源:REDHAT
名称:RHSA-2002:243
链接:http://www.redhat.com/support/errata/RHSA-2002-243.html
来源:REDHAT
名称:RHSA-2002:222
链接:http://www.redhat.com/support/errata/RHSA-2002-222.html
来源:OSVDB
名称:862
链接:http://www.osvdb.org/862
来源:ENGARDE
名称:ESA-20021007-024