Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is not defined, allows remote attackers to inject arbitrary web script or HTML via the P parameter using the UTF-7 charset. NOTE: it could be argued that this issue is due to a design limitation of browsers that attempt to perform automatic content type detection.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apache Mod_AutoIndex.C 未定义字符跨站脚本攻击漏洞
Vulnerability Description
Apache HTTP Server中的mod_autoindex.c存在跨站脚本攻击漏洞,当服务器发生页面的字符集没有明确定义时,远程攻击者可以借助利用UTF-7 字符集的p参数注入任意web脚本或HTML。
CVSS Information
N/A
Vulnerability Type
N/A