CVE-2007-6203
EPSS 80.7%
描述
Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "413 Request Entity Too Large" error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated via an HTTP request containing an invalid Content-length value, a similar issue to CVE-2006-3918.
如何修補 CVE-2007-6203
要修補 CVE-2007-6203,請將受影響套件升級到下列已修補版本。
- Debian/apache2—升級至 2.2.6-3 或更新版本
CVE-2007-6203 正在被利用嗎?
可能 — EPSS 為 80.7%,屬於高被利用機率區間,建議優先修補。
受影響套件(1)
- from 0, < 2.2.6-3