Release date:
Updated on:
Affected Systems:
Apache Group Apache 2.4.2
Description:
--------------------------------------------------------------------------------
Bugtraq id: 55131
Cve id: CVE-2012-2687, CVE-2012-3502
Apache HTTP Server (Apache) is an open source web Server of the Apache Software Foundation. It can run in most computer operating systems. It is widely used for its multi-platform and security, is one of the most popular Web server software.
Apache HTTP Server has the HTML injection vulnerability and Information Leakage vulnerability. Attackers can exploit these vulnerabilities to obtain sensitive information and execute arbitrary script code in the browsers of the affected sites, attackers can steal cookie authentication creden。 or control the appearance of the site.
<* Source: Rainer Jung
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.apache.org