2.6
CVSSv2

CVE-2003-1581

Published: 05/02/2010 Updated: 08/02/2010
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, allows remote malicious users to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by injecting XSS sequences, related to an "Inverse Lookup Log Corruption (ILLC)" issue.

Vulnerable Product Search on Vulmon Subscribe to Product

apache http server 2.0.44

Vendor Advisories

Debian Bug report logs - #570740 apache: log file injection Package: apache2; Maintainer for apache2 is Debian Apache Maintainers <debian-apache@listsdebianorg>; Source for apache2 is src:apache2 (PTS, buildd, popcon) Reported by: Michael Gilbert <michaelsgilbert@gmailcom> Date: Sun, 21 Feb 2010 06:33:51 UTC Se ...