CVE-2007-6203

Source
https://cve.org/CVERecord?id=CVE-2007-6203
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2007-6203.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2007-6203
Downstream
Published
2007-12-03T22:46:00Z
Modified
2025-08-09T19:01:27Z
Summary
[none]
Details

Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "413 Request Entity Too Large" error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated via an HTTP request containing an invalid Content-length value, a similar issue to CVE-2006-3918.

References

Affected packages