Vulnerability Database

296,746

Total vulnerabilities in the database

CVE-2002-0840

Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors via the Host: header, a different vulnerability than CAN-2002-1157.

  • Published: Oct 11, 2002
  • Updated: Apr 13, 2023
  • CVE: CVE-2002-0840
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 6.8
  • AV:N/AC:M/Au:N/C:P/I:P/A:P

No CWE or OWASP classifications available.

Software From Fixed in
apache / http_server 2.0.42 2.0.42.x
oracle / application_server 9.0.2.1 9.0.2.1.x
apache / http_server 1.3.23 1.3.23.x
oracle / oracle9i 9.0.1 9.0.1.x
oracle / oracle9i 9.0.2 9.0.2.x
oracle / oracle8i 8.1.7_.0.0_enterprise 8.1.7_.0.0_enterprise.x
oracle / database_server 8.1.7 8.1.7.x
apache / http_server 2.0.35 2.0.35.x
apache / http_server 2.0.37 2.0.37.x
apache / http_server 1.3.1 1.3.1.x
apache / http_server 1.3.25 1.3.25.x
oracle / oracle9i 9.0 9.0.x
apache / http_server 1.3.19 1.3.19.x
oracle / database_server 9.2.1 9.2.1.x
apache / http_server 2.0.39 2.0.39.x
apache / http_server 1.3.24 1.3.24.x
oracle / application_server 9.0.2-r2 9.0.2-r2.x
apache / http_server 1.3.20 1.3.20.x
apache / http_server 1.3.6 1.3.6.x
apache / http_server 2.0.41 2.0.41.x
oracle / oracle8i 8.1.7.1 8.1.7.1.x
oracle / oracle8i 8.1.7 8.1.7.x
apache / http_server 1.3.4 1.3.4.x
oracle / oracle8i 8.1.7_.1.0_enterprise 8.1.7_.1.0_enterprise.x
apache / http_server 1.3.18 1.3.18.x
apache / http_server 2.0.32 2.0.32.x
oracle / oracle9i 9.0.1.3 9.0.1.3.x
oracle / application_server 1.0.2.1s 1.0.2.1s.x
apache / http_server 2.0.38 2.0.38.x
apache / http_server 1.3 1.3.x
apache / http_server 1.3.12 1.3.12.x
oracle / application_server 9.0.2 9.0.2.x
apache / http_server 1.3.3 1.3.3.x
apache / http_server 1.3.17 1.3.17.x
oracle / oracle9i 9.0.1.2 9.0.1.2.x
apache / http_server 1.3.26 1.3.26.x
apache / http_server 1.3.9 1.3.9.x
apache / http_server 2.0.40 2.0.40.x
apache / http_server 2.0.36 2.0.36.x
apache / http_server 1.3.14 1.3.14.x
apache / http_server 1.3.22 1.3.22.x
apache / http_server 1.3.11 1.3.11.x
oracle / application_server 1.0.2.2 1.0.2.2.x
apache / http_server 2.0.28 2.0.28.x
oracle / database_server 9.2.2 9.2.2.x
apache / http_server 2.0 2.0.x
oracle / application_server 1.0.2 1.0.2.x