Description
This version of Apache is vulnerable to HTML injection (including
malicious Javascript code) through "Expect" header. Until now it was not classified as a security vulnerability, since an attacker has no way to influence the Expect header to send the victim to a target website. However, according to Amit Klein's paper: "Forging HTTP request headers with Flash" there is a working cross site scripting (XSS) attack against Apache 1.3.34, 2.0.57 and 2.2.1 (as long as the client browser is IE or Firefox, and it supports Flash 6/7+).
Affected Apache versions (up to 1.3.34/2.0.57/2.2.1).
Remediation
Upgrade to the latest Apache versions. This flaw has been corrected in Apache versions (1.3.35/2.0.58/2.2.2)
References
Related Vulnerabilities
MySQL CVE-2022-21265 Vulnerability (CVE-2022-21265)
OpenSSL Other Vulnerability (CVE-2003-0544)
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-1000862)
Internet Information Services Other Vulnerability (CVE-2000-0304)
WordPress Plugin Advanced Access Manager Cross-Site Scripting (6.7.9)