CVE-2002-0840 (CNNVD-200210-265)
MEDIUM
有利用代码
中文标题:
Apache Web Server 安全漏洞
英文标题:
Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and ...
CVSS分数:
6.8
发布时间:
2004-09-01 04:00:00
漏洞类型:
其他
状态:
PUBLISHED
数据质量分数:
0.30
数据版本:
v4
漏洞描述
中文描述:
Apache是一款广泛使用的开放源代码WEB服务程序。Apache的对默认错误页面的处理存在问题,攻击者可以利用此漏洞执行跨站脚本攻击。起因是没有正确的过滤SSI错误页面的恶意HTML代码。攻击者可以利用这个漏洞在访问恶意链接的客户端执行HTML和脚本代码,导致控制Web内容或窃取基于cookie的认证凭证。请注意仅在UseCanonicalName设置为Off且服务器运行在使用了通配符DNS的域中的情况下才可能利用这个漏洞。
英文描述:
Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors via the Host: header, a different vulnerability than CAN-2002-1157.
CWE类型:
(暂无数据)
标签:
remote
multiple
mattmurphy
OSVDB-862
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| apache | http_server | 1.3 | - | - |
cpe:2.3:a:apache:http_server:1.3:*:*:*:*:*:*:*
|
| apache | http_server | 1.3.1 | - | - |
cpe:2.3:a:apache:http_server:1.3.1:*:*:*:*:*:*:*
|
| apache | http_server | 1.3.3 | - | - |
cpe:2.3:a:apache:http_server:1.3.3:*:*:*:*:*:*:*
|
| apache | http_server | 1.3.4 | - | - |
cpe:2.3:a:apache:http_server:1.3.4:*:*:*:*:*:*:*
|
| apache | http_server | 1.3.6 | - | - |
cpe:2.3:a:apache:http_server:1.3.6:*:*:*:*:*:*:*
|
| apache | http_server | 1.3.9 | - | - |
cpe:2.3:a:apache:http_server:1.3.9:*:*:*:*:*:*:*
|
| apache | http_server | 1.3.11 | - | - |
cpe:2.3:a:apache:http_server:1.3.11:*:*:*:*:*:*:*
|
| apache | http_server | 1.3.12 | - | - |
cpe:2.3:a:apache:http_server:1.3.12:*:*:*:*:*:*:*
|
| apache | http_server | 1.3.14 | - | - |
cpe:2.3:a:apache:http_server:1.3.14:*:*:*:*:*:*:*
|
| apache | http_server | 1.3.17 | - | - |
cpe:2.3:a:apache:http_server:1.3.17:*:*:*:*:*:*:*
|
| apache | http_server | 1.3.18 | - | - |
cpe:2.3:a:apache:http_server:1.3.18:*:*:*:*:*:*:*
|
| apache | http_server | 1.3.19 | - | - |
cpe:2.3:a:apache:http_server:1.3.19:*:*:*:*:*:*:*
|
| apache | http_server | 1.3.20 | - | - |
cpe:2.3:a:apache:http_server:1.3.20:*:*:*:*:*:*:*
|
| apache | http_server | 1.3.22 | - | - |
cpe:2.3:a:apache:http_server:1.3.22:*:*:*:*:*:*:*
|
| apache | http_server | 1.3.23 | - | - |
cpe:2.3:a:apache:http_server:1.3.23:*:*:*:*:*:*:*
|
| apache | http_server | 1.3.24 | - | - |
cpe:2.3:a:apache:http_server:1.3.24:*:*:*:*:*:*:*
|
| apache | http_server | 1.3.25 | - | - |
cpe:2.3:a:apache:http_server:1.3.25:*:*:*:*:*:*:*
|
| apache | http_server | 1.3.26 | - | - |
cpe:2.3:a:apache:http_server:1.3.26:*:*:*:*:*:*:*
|
| apache | http_server | 2.0 | - | - |
cpe:2.3:a:apache:http_server:2.0:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.28 | - | - |
cpe:2.3:a:apache:http_server:2.0.28:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.32 | - | - |
cpe:2.3:a:apache:http_server:2.0.32:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.35 | - | - |
cpe:2.3:a:apache:http_server:2.0.35:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.36 | - | - |
cpe:2.3:a:apache:http_server:2.0.36:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.37 | - | - |
cpe:2.3:a:apache:http_server:2.0.37:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.38 | - | - |
cpe:2.3:a:apache:http_server:2.0.38:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.39 | - | - |
cpe:2.3:a:apache:http_server:2.0.39:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.40 | - | - |
cpe:2.3:a:apache:http_server:2.0.40:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.41 | - | - |
cpe:2.3:a:apache:http_server:2.0.41:*:*:*:*:*:*:*
|
| apache | http_server | 2.0.42 | - | - |
cpe:2.3:a:apache:http_server:2.0.42:*:*:*:*:*:*:*
|
| oracle | application_server | 1.0.2 | - | - |
cpe:2.3:a:oracle:application_server:1.0.2:*:*:*:*:*:*:*
|
| oracle | application_server | 1.0.2.1s | - | - |
cpe:2.3:a:oracle:application_server:1.0.2.1s:*:*:*:*:*:*:*
|
| oracle | application_server | 1.0.2.2 | - | - |
cpe:2.3:a:oracle:application_server:1.0.2.2:*:*:*:*:*:*:*
|
| oracle | application_server | 9.0.2 | - | - |
cpe:2.3:a:oracle:application_server:9.0.2:*:*:*:*:*:*:*
|
| oracle | application_server | 9.0.2.1 | - | - |
cpe:2.3:a:oracle:application_server:9.0.2.1:*:*:*:*:*:*:*
|
| oracle | database_server | 8.1.7 | - | - |
cpe:2.3:a:oracle:database_server:8.1.7:*:*:*:*:*:*:*
|
| oracle | database_server | 9.2.1 | - | - |
cpe:2.3:a:oracle:database_server:9.2.1:*:*:*:*:*:*:*
|
| oracle | database_server | 9.2.2 | - | - |
cpe:2.3:a:oracle:database_server:9.2.2:*:*:*:*:*:*:*
|
| oracle | oracle8i | 8.1.7 | - | - |
cpe:2.3:a:oracle:oracle8i:8.1.7:*:*:*:*:*:*:*
|
| oracle | oracle8i | 8.1.7.1 | - | - |
cpe:2.3:a:oracle:oracle8i:8.1.7.1:*:*:*:*:*:*:*
|
| oracle | oracle8i | 8.1.7_.0.0_enterprise | - | - |
cpe:2.3:a:oracle:oracle8i:8.1.7_.0.0_enterprise:*:*:*:*:*:*:*
|
| oracle | oracle8i | 8.1.7_.1.0_enterprise | - | - |
cpe:2.3:a:oracle:oracle8i:8.1.7_.1.0_enterprise:*:*:*:*:*:*:*
|
| oracle | oracle9i | 9.0 | - | - |
cpe:2.3:a:oracle:oracle9i:9.0:*:*:*:*:*:*:*
|
| oracle | oracle9i | 9.0.1 | - | - |
cpe:2.3:a:oracle:oracle9i:9.0.1:*:*:*:*:*:*:*
|
| oracle | oracle9i | 9.0.1.2 | - | - |
cpe:2.3:a:oracle:oracle9i:9.0.1.2:*:*:*:*:*:*:*
|
| oracle | oracle9i | 9.0.1.3 | - | - |
cpe:2.3:a:oracle:oracle9i:9.0.1.3:*:*:*:*:*:*:*
|
| oracle | oracle9i | 9.0.2 | - | - |
cpe:2.3:a:oracle:oracle9i:9.0.2:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
(暂无数据)
英文解决方案:
(暂无数据)
临时解决方案:
(暂无数据)
参考链接
DSA-188
vendor-advisory
cve.org
访问
cve.org
无标题
x_refsource_CONFIRM
cve.org
访问
cve.org
ESA-20021007-024
vendor-advisory
cve.org
访问
cve.org
HPSBUX0210-224
vendor-advisory
cve.org
访问
cve.org
DSA-187
vendor-advisory
cve.org
访问
cve.org
无标题
x_refsource_CONFIRM
cve.org
访问
cve.org
DSA-195
vendor-advisory
cve.org
访问
cve.org
20021003 [OpenPKG-SA-2002.009] OpenPKG Security Advisory (apache)
mailing-list
cve.org
访问
cve.org
MDKSA-2002:068
vendor-advisory
cve.org
访问
cve.org
CLA-2002:530
vendor-advisory
cve.org
访问
cve.org
20021017 TSLSA-2002-0069-apache
mailing-list
cve.org
访问
cve.org
20021002 Apache 2 Cross-Site Scripting
mailing-list
cve.org
访问
cve.org
RHSA-2002:243
vendor-advisory
cve.org
访问
cve.org
862
vdb-entry
cve.org
访问
cve.org
RHSA-2002:222
vendor-advisory
cve.org
访问
cve.org
RHSA-2003:106
vendor-advisory
cve.org
访问
cve.org
RHSA-2002:251
vendor-advisory
cve.org
访问
cve.org
apache-http-host-xss(10241)
vdb-entry
cve.org
访问
cve.org
20021105-02-I
vendor-advisory
cve.org
访问
cve.org
20021002 Apache 2 Cross-Site Scripting
mailing-list
cve.org
访问
cve.org
VU#240329
third-party-advisory
cve.org
访问
cve.org
5847
vdb-entry
cve.org
访问
cve.org
RHSA-2002:248
vendor-advisory
cve.org
访问
cve.org
RHSA-2002:244
vendor-advisory
cve.org
访问
cve.org
[httpd-cvs] 20190815 svn commit: r1048742 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html
mailing-list
cve.org
访问
cve.org
[httpd-cvs] 20190815 svn commit: r1048743 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html
mailing-list
cve.org
访问
cve.org
[httpd-cvs] 20200401 svn commit: r1058586 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html
mailing-list
cve.org
访问
cve.org
[httpd-cvs] 20200401 svn commit: r1058587 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html
mailing-list
cve.org
访问
cve.org
[httpd-cvs] 20210330 svn commit: r1073139 [1/13] - in /websites/staging/httpd/trunk/content: ./ security/json/
mailing-list
cve.org
访问
cve.org
[httpd-cvs] 20210330 svn commit: r1073140 [1/4] - in /websites/staging/httpd/trunk/content: ./ security/cvejsontohtml.py security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html
mailing-list
cve.org
访问
cve.org
[httpd-cvs] 20210330 svn commit: r1073140 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/cvejsontohtml.py security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html
mailing-list
cve.org
访问
cve.org
[httpd-cvs] 20210330 svn commit: r1073143 [2/3] - in /websites/staging/httpd/trunk/content: ./ security/
mailing-list
cve.org
访问
cve.org
[httpd-cvs] 20210330 svn commit: r1073149 [2/13] - in /websites/staging/httpd/trunk/content: ./ security/ security/json/
mailing-list
cve.org
访问
cve.org
[httpd-cvs] 20210330 svn commit: r1073149 [1/13] - in /websites/staging/httpd/trunk/content: ./ security/ security/json/
mailing-list
cve.org
访问
cve.org
[httpd-cvs] 20210603 svn commit: r1075360 [1/3] - in /websites/staging/httpd/trunk/content: ./ security/json/CVE-2021-31618.json security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html
mailing-list
cve.org
访问
cve.org
[httpd-cvs] 20210606 svn commit: r1075470 [1/4] - in /websites/staging/httpd/trunk/content: ./ security/json/CVE-2020-13938.json security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html
mailing-list
cve.org
访问
cve.org
[httpd-cvs] 20210606 svn commit: r1075470 [2/4] - in /websites/staging/httpd/trunk/content: ./ security/json/CVE-2020-13938.json security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html
mailing-list
cve.org
访问
cve.org
ExploitDB EDB-21885
EXPLOIT
exploitdb
访问
exploitdb
Download Exploit EDB-21885
EXPLOIT
exploitdb
访问
exploitdb
CVE Reference: CVE-2002-0840
ADVISORY
cve.org
访问
cve.org
CVSS评分详情
6.8
MEDIUM
CVSS向量:
AV:N/AC:M/Au:N/C:P/I:P/A:P
CVSS版本:
2.0
机密性
PARTIAL
完整性
PARTIAL
可用性
PARTIAL
时间信息
发布时间:
2004-09-01 04:00:00
修改时间:
2024-08-08 03:03:48
创建时间:
2025-11-11 15:32:16
更新时间:
2025-11-11 16:16:36
利用信息
此漏洞有可利用代码!
利用代码数量:
1
利用来源:
未知
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2002-0840 |
2025-11-11 15:17:24 | 2025-11-11 07:32:16 |
| NVD | nvd_CVE-2002-0840 |
2025-11-11 14:50:27 | 2025-11-11 07:41:02 |
| CNNVD | cnnvd_CNNVD-200210-265 |
2025-11-11 15:08:41 | 2025-11-11 07:48:49 |
| EXPLOITDB | exploitdb_EDB-21885 |
2025-11-11 15:05:28 | 2025-11-11 08:16:36 |
版本与语言
当前版本:
v4
主要语言:
EN
支持语言:
EN
ZH
其他标识符:
:
:
安全公告
暂无安全公告信息
变更历史
v4
EXPLOITDB
2025-11-11 16:16:36
references_count: 37 → 40; tags_count: 0 → 4; data_sources: ['cnnvd', 'cve', 'nvd'] → ['cnnvd', 'cve', 'exploitdb', 'nvd']
查看详细变更
- references_count: 37 -> 40
- tags_count: 0 -> 4
- data_sources: ['cnnvd', 'cve', 'nvd'] -> ['cnnvd', 'cve', 'exploitdb', 'nvd']
v3
CNNVD
2025-11-11 15:48:49
vulnerability_type: 未提取 → 其他; cnnvd_id: 未提取 → CNNVD-200210-265; data_sources: ['cve', 'nvd'] → ['cnnvd', 'cve', 'nvd']
查看详细变更
- vulnerability_type: 未提取 -> 其他
- cnnvd_id: 未提取 -> CNNVD-200210-265
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
v2
NVD
2025-11-11 15:41:02
cvss_score: 未提取 → 6.8; cvss_vector: NOT_EXTRACTED → AV:N/AC:M/Au:N/C:P/I:P/A:P; cvss_version: NOT_EXTRACTED → 2.0; affected_products_count: 0 → 46; data_sources: ['cve'] → ['cve', 'nvd']
查看详细变更
- cvss_score: 未提取 -> 6.8
- cvss_vector: NOT_EXTRACTED -> AV:N/AC:M/Au:N/C:P/I:P/A:P
- cvss_version: NOT_EXTRACTED -> 2.0
- affected_products_count: 0 -> 46
- data_sources: ['cve'] -> ['cve', 'nvd']