CVE Vulnerabilities

CVE-2002-1157

Published: Nov 04, 2002 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Cross-site scripting vulnerability in the mod_ssl Apache module 2.8.9 and earlier, when UseCanonicalName is off and wildcard DNS is enabled, allows remote attackers to execute script as other web site visitors, via the server name in an HTTPS response on the SSL port, which is used in a self-referencing URL, a different vulnerability than CAN-2002-0840.

Affected Software

Name Vendor Start Version End Version
Mod_ssl Mod_ssl * 2.8.9 (including)
Red Hat Enterprise Linux AS (Advanced Server) version 2.1 RedHat *
Red Hat Linux 6.2 RedHat *
Red Hat Linux 7.0 RedHat *
Red Hat Linux 7.1 RedHat *
Red Hat Linux 7.1 RedHat *
Red Hat Linux 7.2 RedHat *
Red Hat Linux 7.3 RedHat *
Red Hat Linux 8.0 RedHat *
Red Hat Linux Advanced Workstation 2.1 RedHat *
Red Hat Stronghold 3 RedHat *
Red Hat Stronghold 4 RedHat *
Stronghold 4 for Red Hat Enterprise Linux RedHat *
Libapache-mod-ssl Ubuntu dapper *
Libapache-mod-ssl Ubuntu edgy *
Libapache-mod-ssl Ubuntu feisty *

References