HPSBMU02786Vendor advisory
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03360041 CVE-2012-0053
Apache - httpOnly Cookie Disclosure
Record summary
CVE-2012-0053 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.
Description
protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with crafted web script.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBApache - httpOnly Cookie DisclosureExploitDB exploitby pilateNot analyzed1 file
References
Showing 12 of 68httpd.apache.orgConfirmation
http://httpd.apache.org/security/vulnerabilities_22.html kb.juniper.netConfirmation
http://kb.juniper.net/JSA10585 APPLE-SA-2012-09-19-2Vendor advisory
http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html openSUSE-SU-2012:0314Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00026.html SUSE-SU-2012:0323Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2012-03/msg00002.html SSRT100772Vendor advisory
http://marc.info/?l=bugtraq&m=133294460209056&w=2 HPSBUX02761Vendor advisory
http://marc.info/?l=bugtraq&m=133494237717847&w=2 SSRT100852Vendor advisory
http://marc.info/?l=bugtraq&m=133951357207000&w=2 SSRT101112Vendor advisory
http://marc.info/?l=bugtraq&m=136441204617335&w=2 RHSA-2012:0128Vendor advisory
http://rhn.redhat.com/errata/RHSA-2012-0128.html RHSA-2012:0542Vendor advisory
http://rhn.redhat.com/errata/RHSA-2012-0542.html