CVE DATABASE / CVE-2008-0005
CVE-2008-0005
CVSS 4.3 · MEDIUM
Summary
mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 encoding.
CVSS 2.0 breakdown
| Base score | 4.3 (MEDIUM) |
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
| Attack vector | NETWORK |
| Attack complexity | MEDIUM |
| Confidentiality | NONE |
| Integrity | PARTIAL |
| Availability | NONE |
Weakness type (CWE)
Affected products
Apache http serverFedoraproject fedoraCanonical ubuntu linux
Check this CVE live
Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.
References
- http://docs.info.apple.com/article.html?artnum=307562
- http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00004.html
- http://lists.vmware.com/pipermail/security-announce/2009/000062.html
- http://marc.info/?l=bugtraq&m=124654546101607&w=2
- http://marc.info/?l=bugtraq&m=125631037611762&w=2
- http://marc.info/?l=bugtraq&m=130497311408250&w=2
- http://secunia.com/advisories/28467
- http://secunia.com/advisories/28471
- http://secunia.com/advisories/28526
- http://secunia.com/advisories/28607
- http://secunia.com/advisories/28749
- http://secunia.com/advisories/28977
- http://secunia.com/advisories/29348
- http://secunia.com/advisories/29420
Data: NIST NVD. NVD last modified 2026-04-23. Always verify against the vendor advisory before acting.