HPSBUX02365Vendor advisory
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01539432 CVE-2008-2168
Microsoft Internet Explorer 2 - UTF-7 HTTP Response Handling
Record summary
CVE-2008-2168 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.
Description
Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded URLs that are not properly handled when displaying the 403 Forbidden error page.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBMicrosoft Internet Explorer 2 - UTF-7 HTTP Response HandlingExploitDB exploitby Yaniv MironNot analyzed1 file
References
Showing 12 of 16SSRT090085Vendor advisory
http://marc.info/?l=bugtraq&m=124654546101607&w=2 HPSBUX02465Vendor advisory
http://marc.info/?l=bugtraq&m=125631037611762&w=2 31651Third-party advisory
http://secunia.com/advisories/31651 34219Third-party advisory
http://secunia.com/advisories/34219 35650Third-party advisory
http://secunia.com/advisories/35650 3889Third-party advisory
http://securityreason.com/securityalert/3889 20080508 Apache Server HTML Injection and UTF-7 XSS Vulnerabilitymailing list
http://www.securityfocus.com/archive/1/491862/100/0/threaded 20080510 Re: Apache Server HTML Injection and UTF-7 XSS Vulnerabilitymailing list
http://www.securityfocus.com/archive/1/491901/100/0/threaded 20080510 Re: Re: Apache Server HTML Injection and UTF-7 XSS Vulnerabilitymailing list
http://www.securityfocus.com/archive/1/491930/100/0/threaded 20080512 Re: Re: Re: Apache Server HTML Injection and UTF-7 XSS Vulnerabilitymailing list
http://www.securityfocus.com/archive/1/491967/100/0/threaded 29112vdb entry
http://www.securityfocus.com/bid/29112