CVE-2006-5752
EPSS 27.8%
描述
Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when ExtendedStatus is enabled and a public server-status page is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving charsets with browsers that perform "charset detection" when the content-type is not specified.
如何修補 CVE-2006-5752
要修補 CVE-2006-5752,請將受影響套件升級到下列已修補版本。
- Debian/apache2—升級至 2.2.4-2 或更新版本
CVE-2006-5752 正在被利用嗎?
中等 — EPSS 為 27.8%,可持續追蹤但非最高優先。
受影響套件(1)
- from 0, < 2.2.4-2