CVE-2007-3008

Description

From CVE.org

Mbedthis AppWeb before 2.2.2 enables the HTTP TRACE method, which has unspecified impact probably related to remote information leaks and cross-site tracing (XST) attacks, a related issue to CVE-2004-2320 and CVE-2005-3398.

Statement

The Apache Software Foundation do not treat this as a security issue. A configuration change can be made to disable the ability to respond to HTTP TRACE requests if required.

For more information please see: http://www.apacheweek.com/issues/03-01-24#news

Frequently Asked Questions

Want to get errata notifications? Sign up here.