Oval Definition:oval:org.mitre.oval:def:21751
Revision Date:2014-05-26Version:20
Title:ELSA-2008:0967: httpd security and bug fix update (Moderate)
Description:Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web script or HTML via a wildcard in the last directory component in the pathname in an FTP URI.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2008-2364
CVE-2008-2939
ELSA-2008:0967-01
Platform(s):Oracle Linux 5
Product(s):httpd
Definition Synopsis
  • Oracle Linux 5.x
  • AND rpm test
  • httpd-manual is earlier than 0:2.2.3-11.el5_2.4
  • OR httpd-devel is earlier than 0:2.2.3-11.el5_2.4
  • OR mod_ssl is earlier than 0:2.2.3-11.el5_2.4
  • OR httpd is earlier than 0:2.2.3-11.el5_2.4
  • BACK