Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "413 Request Entity Too Large" error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated via an HTTP request containing an invalid Content-length value, a similar issue to CVE-2006-3918.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apache HTTP Server HTTP 413错误页面跨站脚本漏洞
Vulnerability Description
Apache HTTP Server是一款流行的Web服务器。 Apache HTTP Server处理畸形用户请求时存在漏洞,远程攻击者可能利用此漏洞获取脚本源码。 如果远程用户提交的畸形HTTP请求承载有以下形式之一负载(如JavaScript)和无效长度数据的话,就会导致Apache HTTP服务器返回客户端所提供的脚本代码: 两个Content-length头等于0,如Content-Length: 0[LF]Content-Length: 0 一个Content-length头等于两个值,如Co
CVSS Information
N/A
Vulnerability Type
N/A