CVE-2006-3918
Apache HTTP Server < 1.3.35 - XSS
Title source: ruleDescription
http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected back in an error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated using a Flash SWF file.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Thiago Zaninotti · textremotelinux
https://www.exploit-db.com/exploits/28424
References (56)
... and 36 more
Scores
EPSS
0.9137
EPSS Percentile
99.6%
Classification
CWE
CWE-79
Status
draft
Affected Products (8)
apache/http_server
< 1.3.35
debian/debian_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
redhat/enterprise_linux_server
redhat/enterprise_linux_workstation
Timeline
Published
Jul 28, 2006
Tracked Since
Feb 18, 2026