Upstream information
Description
Cross-site scripting (XSS) vulnerability in balancer-manager in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via the (1) ss, (2) wr, or (3) rr parameters, or (4) the URL.SUSE information
Overall state of this security issue: Resolved
This issue is currently not rated by SUSE as it is not affecting the SUSE Enterprise products.
National Vulnerability Database | |
---|---|
Base Score | 3.5 |
Vector | AV:N/AC:M/Au:S/C:N/I:P/A:N |
Access Vector | Network |
Access Complexity | Medium |
Authentication | Single |
Confidentiality Impact | None |
Integrity Impact | Partial |
Availability Impact | None |
SUSE Security Advisories:
- SUSE-SA:2008:021, published Fri, 04 Apr 2008 16:00:00 +0000
List of released packages
Product(s) | Fixed package version(s) | References |
---|---|---|
SUSE Linux Enterprise Desktop 11 SP4 SUSE Linux Enterprise Server for SAP Applications 11 SP4 SUSE Linux Enterprise Software Development Kit 11 SP4 |
| Patchnames: SUSE Linux Enterprise Software Development Kit 11 SP4 GA apache2-2.2.12-1.51.52.1 |
SUSE Linux Enterprise Server 11 SP1 |
| Patchnames: SUSE Linux Enterprise Server 11 SP1 GA apache2-2.2.10-2.24.5 |
SUSE Linux Enterprise Server 11 SP2 |
| Patchnames: SUSE Linux Enterprise Server 11 SP2 GA apache2-2.2.12-1.28.1 |
SUSE Linux Enterprise Server 11 SP3 |
| Patchnames: SUSE Linux Enterprise Server 11 SP3 GA apache2-2.2.12-1.38.2 |
SUSE Linux Enterprise Server 11 SP4 |
| Patchnames: SUSE Linux Enterprise Server 11 SP4 GA apache2-2.2.12-1.51.52.1 SUSE Linux Enterprise Software Development Kit 11 SP4 GA apache2-2.2.12-1.51.52.1 |
openSUSE Tumbleweed |
| Patchnames: openSUSE Tumbleweed GA apache2-2.4.49-1.1 |
SUSE Timeline for this CVE
CVE page created: Tue Jul 9 16:46:00 2013CVE page last modified: Fri Oct 7 12:45:39 2022