Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2002-1157 | First vendor Publication | 2002-11-04 |
Vendor | Cve | Last vendor Modification | 2024-11-20 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 7.5 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Cross-site scripting vulnerability in the mod_ssl Apache module 2.8.9 and earlier, when UseCanonicalName is off and wildcard DNS is enabled, allows remote attackers to execute script as other web site visitors, via the server name in an HTTPS response on the SSL port, which is used in a self-referencing URL, a different vulnerability than CAN-2002-0840. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1157 |
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2008-01-17 | Name : Debian Security Advisory DSA 181-1 (libapache-mod-ssl) File : nvt/deb_181_1.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
2107 | Apache HTTP Server mod_ssl Host: Header XSS Apache mod_ssl contains a flaw that allows a remote Cross Site Scripting attack. This flaw exists because the application does not validate server signature data upon submission to the SSI error page. This could allow a user to send a specially crafted request that would execute the embedded script within the security context of the hosting site. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2004-09-29 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-181.nasl - Type : ACT_GATHER_INFO |
2004-07-31 | Name : The remote Mandrake Linux host is missing a security update. File : mandrake_MDKSA-2002-072.nasl - Type : ACT_GATHER_INFO |
2004-07-06 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2002-251.nasl - Type : ACT_GATHER_INFO |
2003-05-12 | Name : The remote web server module has a cross-site scripting vulnerability. File : mod_ssl_wildcard_dns_xss.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:23:45 |
|
2024-11-28 12:05:12 |
|
2021-05-05 01:01:20 |
|
2021-05-04 12:01:46 |
|
2021-04-22 01:01:53 |
|
2020-05-24 01:01:10 |
|
2020-05-23 00:15:05 |
|
2016-06-28 15:00:14 |
|
2016-04-26 12:16:13 |
|
2014-02-17 10:25:06 |
|
2013-05-11 12:12:00 |
|