Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2007-4465

Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is not defined, allows remote attackers to inject arbitrary web script or HTML via the P parameter using the UTF-7 charset. NOTE: it could be argued that this issue is due to a design limitation of browsers that attempt to perform automatic content type detection.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.076
EPSS Ranking 91.5%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
References
Products affected by CVE-2007-4465


Contact Us

Shodan ® - All rights reserved