Apache version older than 1.3.39

Description
  • <div class="bb-coolbox"><span class="bb-dark">This alert was generated using only banner information. It may be a false positive. </span></div><br/><strong>Security fixes in Apache version 1.3.39:</strong><br/><ul> <li>CVE-2006-5752 (cve.mitre.org) mod_status: Fix a possible XSS attack against a site with a public server-status page and ExtendedStatus enabled, for browsers which perform charset "detection". Reported by Stefan Esser. [Joe Orton]</li> <li>CVE-2007-3304 (cve.mitre.org) Ensure that the parent process cannot be forced to kill non-child processes by checking scoreboard PID data with parent process privately stored PID data. [Jim Jagielski]</li> </ul><br/><span class="bb-navy">Affected Apache versions (up to 1.3.38).</span><br/>
Remediation
  • Upgrade Apache to the latest version.
References