peter bassill · operator
$ cve CVE-2012-0053 JSON

CVE-2012-0053 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 82.2% (pctl 100)

Patch early

A public exploit exists.

Description

protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with crafted web script.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
EPSS82.2% — more likely to be exploited than 100% of all CVEs
On CISA KEVno
Public exploityes
Published2012-01-28
Last modified2026-06-16

Affected (12)

VendorProduct
apachehttp server
debiandebian linux
opensuseopensuse
redhatenterprise linux
redhatenterprise linux desktop
redhatenterprise linux eus
redhatenterprise linux server
redhatenterprise linux workstation
redhatjboss enterprise web server
redhatstorage
suselinux enterprise server
suselinux enterprise software development kit

Public exploits

SourceTitleDate
exploit-dbApache - httpOnly Cookie Disclosure2012-01-31

References

→ the Explorer  ·  watch your stack  ·  NVD