CVE-2007-6388
Publication date 8 January 2008
Last updated 24 July 2024
Ubuntu priority
Cross-site scripting (XSS) vulnerability in mod_status in the Apache HTTP Server 2.2.0 through 2.2.6, 2.0.35 through 2.0.61, and 1.3.2 through 1.3.39, when the server-status page is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Status
Package | Ubuntu Release | Status |
---|---|---|
apache | 9.10 karmic | Not in release |
9.04 jaunty | Not in release | |
8.10 intrepid | Not in release | |
8.04 LTS hardy | Not in release | |
7.10 gutsy | Not in release | |
7.04 feisty | Ignored end of life, was needed | |
6.10 edgy | Ignored end of life, was needed | |
6.06 LTS dapper | Ignored end of life | |
apache2 | 9.10 karmic |
Not affected
|
9.04 jaunty |
Not affected
|
|
8.10 intrepid |
Not affected
|
|
8.04 LTS hardy |
Not affected
|
|
7.10 gutsy |
Fixed 2.2.4-3ubuntu0.1
|
|
7.04 feisty |
Fixed 2.2.3-3.2ubuntu2.1
|
|
6.10 edgy |
Fixed 2.0.55-4ubuntu4.2
|
|
6.06 LTS dapper |
Fixed 2.0.55-4ubuntu2.3
|