Ask the Community
Groups
CVE-2012-2687: Apache HTTPD: XSS in mod_negotiation - Connect IT Community | Kaseya
<main> <article class="userContent"> <h3 data-id="cve-id"><strong>CVE ID</strong></h3> <p>CVE-2012-2687</p> <h3 data-id="description"><strong>DESCRIPTION</strong></h3> <p>Multiple cross-site scripting (XSS) vulnerabilities in the make_variant_list function in mod_negotiation.c in the mod_negotiation module in the Apache HTTP Server 2.4.x before 2.4.3, when the MultiViews option is enabled, allow remote attackers to inject arbitrary web script or HTML via a crafted filename that is not properly handled during construction of a variant list.<br><br>Unitrends assessment: Medium Risk</p> <h3 data-id="resolution"><strong>RESOLUTION</strong></h3> <p>You may already have received the new httpd, but if not, update httpd.<br><br>Fixed in: </p> <ul><li>httpd-2.2.3-74.el5 or later for CentOS5</li> <li>httpd-2.2.15-26.el6 or later for CentOS6</li> </ul> To update to the new version with the fix, either do 'yum update httpd' from the command line, or perform an update from the UI.<h3 data-id="link-to-advisories"><strong>LINK TO ADVISORIES</strong></h3> <p></p> <ul><li><a rel="nofollow" href="/home/leaving?allowTrusted=1&target=https%3A%2F%2Faccess.redhat.com%2Fsecurity%2Fcve%2FCVE-2012-2687">https://access.redhat.com/security/cve/CVE-2012-2687</a></li></ul> </article> </main>