Orange Business Services
Vigil@nce Vigil@nce Vigil@nce
we track for your security since 1999
  home presentation vulnerabilities documentation contact  
subscriber area subscriber area
free access free access
The Vigil@nce team watches vulnerabilities impacting your computers, and then offers solutions, a database and tools to correct them.
recent vulnerabilities recent vulnerabilities
tracked products tracked products
RSS feed RSS feed
vulnerable product
Vulnerabilities of Apache httpd

Apache httpd vulnerability: character injection via mod_rewrite
An attacker can use special characters, which are not filtered by mod_rewrite of Apache httpd 2.2, in order to inject them in the log file.

Apache httpd vulnerability: Cross Site Scripting of mod_proxy_balancer
An attacker can trigger a Cross Site Scripting in Apache httpd mod_proxy_balancer, in order to execute JavaScript code in the context of the web site.

Apache httpd vulnerability: Cross Site Scripting of modules
An attacker can trigger several Cross Site Scripting in the mod_info, mod_status, mod_imagemap, mod_ldap and mod_proxy_ftp modules, in order to execute JavaScript code in the context of the web site.

Apache httpd vulnerability: Cross Site Scripting of mod_negotiation
When an attacker can upload a file in a directory with MultiViews enabled, he can generate a Cross Site Scripting via the module mod_negotiation of Apache httpd.

Apache httpd vulnerability: information disclosure via mod_proxy_ajp ou mod_proxy_http
When Apache httpd is configured as a proxy, with mod_proxy_ajp or mod_proxy_http, an attacker can obtain documents belonging to another user.

Display other vulnerabilities of Apache httpd described by Vigil@nce...

Display information about Apache httpd:



















Copyright 1999-2013 Vigil@nce. Vigil@nce is a service from Orange Business Services. Site map. Legal notice. Version française