CVE-2007-4465
Publication date 14 September 2007
Last updated 24 July 2024
Ubuntu priority
Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is not defined, allows remote attackers to inject arbitrary web script or HTML via the P parameter using the UTF-7 charset. NOTE: it could be argued that this issue is due to a design limitation of browsers that attempt to perform automatic content type detection.
Notes
References
Related Ubuntu Security Notices (USN)
- USN-575-1
- Apache vulnerabilities
- 4 February 2008