CVE-2007-6203
Apache HTTP Server 2.0.x-2.2.x - XSS
Title source: llmDescription
Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "413 Request Entity Too Large" error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated via an HTTP request containing an invalid Content-length value, a similar issue to CVE-2006-3918.
Exploits (1)
exploitdb
SCANNER
VERIFIED
by Adrian Pastor · bashremoteunix
https://www.exploit-db.com/exploits/30835
References (31)
... and 11 more
Scores
EPSS
0.7314
EPSS Percentile
98.8%
Classification
CWE
CWE-79
Status
draft
Affected Products (25)
apache/http_server
apache/http_server
apache/http_server
apache/http_server
apache/http_server
apache/http_server
apache/http_server
apache/http_server
apache/http_server
apache/http_server
apache/http_server
apache/http_server
apache/http_server
apache/http_server
apache/http_server
... and 10 more
Timeline
Published
Dec 03, 2007
Tracked Since
Feb 18, 2026