CVE-2003-1581

The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by injecting XSS sequences, related to an "Inverse Lookup Log Corruption (ILLC)" issue.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:http_server:2.0.44:*:*:*:*:*:*:*

History

No history.

Information

Published : 2010-02-05 22:30

Updated : 2024-02-28 11:41


NVD link : CVE-2003-1581

Mitre link : CVE-2003-1581

CVE.ORG link : CVE-2003-1581


JSON object : View

Products Affected

apache

  • http_server
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')