CVE-2008-2168

Public Date:
2008-05-08
CWE:
CWE-79
Bugzilla:
446352: CVE-2008-2168 httpd: XSS via UTF-7 encoded urls on the 403 Forbidden error page

The MITRE CVE dictionary describes this issue as:

Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded URLs that are not properly handled when displaying the 403 Forbidden error page.

Find out more about CVE-2008-2168 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

This is actually a flaw in browsers that do not derive the response character set as required by RFC 2616. This does not affect the default configuration of Apache httpd in Red Hat products and will only affect customers who have removed the "AddDefaultCharset" directive.
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2008-2168

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.