FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2008-2939

This CVE name corresponds to:

Entered Topic
2009-03-11 apache -- Cross-site scripting vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2008-2939
Phase Assigned(20080630)

Description

Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web script or HTML via a wildcard in the last directory component in the pathname in an FTP URI.

References

Source Reference
BUGTRAQ 20080806 Apache HTTP Server mod_proxy_ftp Wildcard Characters Cross-Site Scripting
BUGTRAQ 20081122 rPSA-2008-0327-1 httpd mod_ssl
BUGTRAQ 20081122 rPSA-2008-0328-1 httpd mod_ssl
MISC http://www.rapid7.com/advisories/R7-0033
CONFIRM http://svn.apache.org/viewvc?view=rev&revision=682868
CONFIRM http://svn.apache.org/viewvc?view=rev&revision=682871
CONFIRM http://svn.apache.org/viewvc?view=rev&revision=682870
CONFIRM http://wiki.rpath.com/Advisories:rPSA-2008-0327
CONFIRM http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0328
CONFIRM http://support.apple.com/kb/HT3549
AIXAPAR PK70197
AIXAPAR PK70937
APPLE APPLE-SA-2009-05-12
HP HPSBUX02401
HP SSRT090005
HP HPSBUX02465
HP SSRT090192
MANDRIVA MDVSA-2008:194
MANDRIVA MDVSA-2008:195
MANDRIVA MDVSA-2009:124
REDHAT RHSA-2008:0967
REDHAT RHSA-2008:0966
SUNALERT 247666
SUSE SUSE-SR:2008:024
UBUNTU USN-731-1
CERT TA09-133A
CERT-VN VU#663763
BID 30560
OVAL oval:org.mitre.oval:def:11316
OVAL oval:org.mitre.oval:def:7716
SECUNIA 34219
SECUNIA 35074
VUPEN ADV-2008-2315
VUPEN ADV-2008-2461
VUPEN ADV-2009-0320
SECTRACK 1020635
SECUNIA 31384
SECUNIA 31673
SECUNIA 32685
SECUNIA 33156
SECUNIA 33797
SECUNIA 32838
VUPEN ADV-2009-1297
XF apache-modproxyftp-xss(44223)