apache-2-xss.txt...

- AV AC AU C I A
发布: 2002-10-02
修订: 2025-04-13

The Apache servers prior to 2.0.43 insecurely include the value of the 'Host:' header field, received from a connected client, into the SSI error pages. This can be abused for remote cross-site scripting. Apache 1.3.x servers are not affected.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息