Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2006-3918

http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected back in an error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated using a Flash SWF file.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.918
EPSS Ranking 99.7%
CVSS Severity
CVSS v2 Score 4.3
References
Products affected by CVE-2006-3918


Contact Us

Shodan ® - All rights reserved