CVE-2007-6203

Apache HTTP Server 2.0.x-2.2.x - XSS

Title source: llm

Description

Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "413 Request Entity Too Large" error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated via an HTTP request containing an invalid Content-length value, a similar issue to CVE-2006-3918.

Exploits (1)

exploitdb SCANNER VERIFIED
by Adrian Pastor · bashremoteunix
https://www.exploit-db.com/exploits/30835

Scores

EPSS 0.7314
EPSS Percentile 98.8%

Classification

CWE
CWE-79
Status draft

Affected Products (25)

apache/http_server
apache/http_server
apache/http_server
apache/http_server
apache/http_server
apache/http_server
apache/http_server
apache/http_server
apache/http_server
apache/http_server
apache/http_server
apache/http_server
apache/http_server
apache/http_server
apache/http_server
... and 10 more

Timeline

Published Dec 03, 2007
Tracked Since Feb 18, 2026