peter bassill · operator
$ cve CVE-2002-0840 JSON

CVE-2002-0840 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 95.1% (pctl 100)

Patch early

A public exploit exists.

Description

Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors via the Host: header, a different vulnerability than CAN-2002-1157.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS95.09% — more likely to be exploited than 100% of all CVEs
On CISA KEVno
Public exploityes
Published2002-10-11
Last modified2026-06-16

Affected (5)

VendorProduct
apachehttp server
oracleapplication server
oracledatabase server
oracleoracle8i
oracleoracle9i

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD