CVE-2016-6812

MEDIUM

Apache CXF < 3.0.12 and 3.1.x < 3.1.9 - Cross-Site Scripting via Matrix Parameters in HTTP Transport Module

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2016-6812. PoCs published by shoucheng3.

AI-analyzed exploit summary The repository appears to be a partial or incomplete snapshot of the Apache CXF project, lacking any exploit code or technical analysis specific to CVE-2016-6812. It contains standard project files (e.g., GitHub workflows, README) but no PoC or vulnerability details.

Description

The HTTP transport module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 uses FormattedServiceListWriter to provide an HTML page which lists the names and absolute URL addresses of the available service endpoints. The module calculates the base URL using the current HttpServletRequest. The calculated base URL is used by FormattedServiceListWriter to build the service endpoint absolute URLs. If the unexpected matrix parameters have been injected into the request URL then these matrix parameters will find their way back to the client in the services list page which represents an XSS risk to the client.

Exploits (1)

nomisec STUB
by shoucheng3 · poc
https://github.com/shoucheng3/asf__cxf_CVE-2016-6812_3-0-11

The repository appears to be a partial or incomplete snapshot of the Apache CXF project, lacking any exploit code or technical analysis specific to CVE-2016-6812. It contains standard project files (e.g., GitHub workflows, README) but no PoC or vulnerability details.

Classification
Stub 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: Apache CXF
No auth needed
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (11)

Core 11
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:0868
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1037543
Issue Tracking, Vendor Advisory x_refsource_confirm
https://issues.apache.org/jira/browse/CXF-6216
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/97582

Scores

CVSS v3 6.1
EPSS 0.0859
EPSS Percentile 92.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (13)
apache/cxf 3.1.0
apache/cxf 3.1.1
apache/cxf 3.1.2
apache/cxf 3.1.3
apache/cxf 3.1.4
apache/cxf 3.1.5
apache/cxf 3.1.6
apache/cxf 3.1.7
apache/cxf 3.1.8
apache/cxf < 3.0.11
... and 3 more
Published Aug 10, 2017
Tracked Since Feb 18, 2026