Apache.Mod.Proxy.Ftp.Wildcard

NameApache.Mod.Proxy.Ftp.Wildcard.Characters.XSS
Release DateSep 23, 2008
SeverityMedium
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems.
DescriptionThis indicates an attack attempt to exploit a Cross-Site Scripting (XSS) vulnerability in Apache.

The vulnerability is caused by an error that occurs when the vulnerable
software handles a URL containing wildcard character in mod_ftp_proxy. A remote attacker may exploit this to execute arbitrary script by enticing user to access a malicious URL.
Affected ProductsApache, HTTP Server 2.0.63
Apache, HTTP Server 2.2.9
Recommended ActionsUpgrade to the latest version,available from the website.
http://httpd.apache.org/
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-2939
Reference/shttp://www.securityfocus.com/bid/30560 (BugTraq)
http://secunia.com/advisories/31384/
Reference: VID-15766