peter bassill · operator
$ cve CVE-2006-3918 JSON

CVE-2006-3918 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 95.1% (pctl 100)

Patch early

A public exploit exists.

Description

http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected back in an error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated using a Flash SWF file.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS95.1% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2006-07-28
Last modified2026-06-16

Affected (5)

VendorProduct
apachehttp server
canonicalubuntu linux
debiandebian linux
redhatenterprise linux server
redhatenterprise linux workstation

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD