CVE Vulnerabilities

CVE-2002-0840

Published: Oct 11, 2002 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is Off and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors via the Host: header, a different vulnerability than CAN-2002-1157.

Affected Software

NameVendorStart VersionEnd Version
Http_serverApache1.3 (including)1.3 (including)
Http_serverApache1.3.1 (including)1.3.1 (including)
Http_serverApache1.3.3 (including)1.3.3 (including)
Http_serverApache1.3.4 (including)1.3.4 (including)
Http_serverApache1.3.6 (including)1.3.6 (including)
Http_serverApache1.3.9 (including)1.3.9 (including)
Http_serverApache1.3.11 (including)1.3.11 (including)
Http_serverApache1.3.12 (including)1.3.12 (including)
Http_serverApache1.3.14 (including)1.3.14 (including)
Http_serverApache1.3.17 (including)1.3.17 (including)
Http_serverApache1.3.18 (including)1.3.18 (including)
Http_serverApache1.3.19 (including)1.3.19 (including)
Http_serverApache1.3.20 (including)1.3.20 (including)
Http_serverApache1.3.22 (including)1.3.22 (including)
Http_serverApache1.3.23 (including)1.3.23 (including)
Http_serverApache1.3.24 (including)1.3.24 (including)
Http_serverApache1.3.25 (including)1.3.25 (including)
Http_serverApache1.3.26 (including)1.3.26 (including)
Http_serverApache2.0 (including)2.0 (including)
Http_serverApache2.0.28 (including)2.0.28 (including)
Http_serverApache2.0.32 (including)2.0.32 (including)
Http_serverApache2.0.35 (including)2.0.35 (including)
Http_serverApache2.0.36 (including)2.0.36 (including)
Http_serverApache2.0.37 (including)2.0.37 (including)
Http_serverApache2.0.38 (including)2.0.38 (including)
Http_serverApache2.0.39 (including)2.0.39 (including)
Http_serverApache2.0.40 (including)2.0.40 (including)
Http_serverApache2.0.41 (including)2.0.41 (including)
Http_serverApache2.0.42 (including)2.0.42 (including)
Application_serverOracle1.0.2 (including)1.0.2 (including)
Application_serverOracle1.0.2.1s (including)1.0.2.1s (including)
Application_serverOracle1.0.2.2 (including)1.0.2.2 (including)
Application_serverOracle9.0.2 (including)9.0.2 (including)
Application_serverOracle9.0.2-r2 (including)9.0.2-r2 (including)
Application_serverOracle9.0.2.1 (including)9.0.2.1 (including)
Database_serverOracle8.1.7 (including)8.1.7 (including)
Database_serverOracle9.2.1 (including)9.2.1 (including)
Database_serverOracle9.2.2 (including)9.2.2 (including)
Oracle8iOracle8.1.7 (including)8.1.7 (including)
Oracle8iOracle8.1.7.1 (including)8.1.7.1 (including)
Oracle8iOracle8.1.7_.0.0_enterprise (including)8.1.7_.0.0_enterprise (including)
Oracle8iOracle8.1.7_.1.0_enterprise (including)8.1.7_.1.0_enterprise (including)
Oracle9iOracle9.0 (including)9.0 (including)
Oracle9iOracle9.0.1 (including)9.0.1 (including)
Oracle9iOracle9.0.1.2 (including)9.0.1.2 (including)
Oracle9iOracle9.0.1.3 (including)9.0.1.3 (including)
Oracle9iOracle9.0.2 (including)9.0.2 (including)
Red Hat Enterprise Linux AS (Advanced Server) version 2.1RedHat*
Red Hat Linux 6.2RedHat*
Red Hat Linux 7.0RedHat*
Red Hat Linux 7.1RedHat*
Red Hat Linux 7.1RedHat*
Red Hat Linux 7.2RedHat*
Red Hat Linux 7.3RedHat*
Red Hat Linux 8.0RedHat*
Red Hat Linux Advanced Workstation 2.1RedHat*
Red Hat Stronghold 3RedHat*
Red Hat Stronghold 4RedHat*
Stronghold 4 for Red Hat Enterprise LinuxRedHat*
ApacheUbuntudapper*
ApacheUbuntuedgy*
ApacheUbuntufeisty*
Apache2Ubuntudapper*
Apache2Ubuntudevel*
Apache2Ubuntuedgy*
Apache2Ubuntufeisty*

References