Description
Multiple cross-site scripting (XSS) vulnerabilities in the make_variant_list function in mod_negotiation.c in the mod_negotiation module in the Apache HTTP Server 2.4.x before 2.4.3, when the MultiViews option is enabled, allow remote attackers to inject arbitrary web script or HTML via a crafted filename that is not properly handled during construction of a variant list.
Remediation
References
Related Vulnerabilities
Joomla! Core 1.5.x Open Redirect (1.5.0 - 1.5.6)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-4295)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-0122)
WordPress Plugin School Management System-WPSchoolPress Multiple Vulnerabilities (2.1.9)