CVE-2006-3918
Description
http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected back in an error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated using a Flash SWF file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Cross-site scripting vulnerability in Apache and IBM HTTP Server due to unsanitized Expect header reflection in error messages.
Vulnerability
The http_protocol.c component in IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, as well as Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected back in an error message. This allows the injection of arbitrary script content into error pages.
Exploitation
An attacker can exploit this vulnerability by crafting a malicious HTTP request containing a specially crafted Expect header. If the request results in an error, the server reflects the Expect header in the error response. Using a client that can send arbitrary headers, such as a Flash SWF file, an attacker can cause a victim's browser to send such a request, leading to execution of attacker-supplied script in the browser's security context of the server.
Impact
Successful exploitation allows the attacker to perform cross-site scripting (XSS) attacks, potentially leading to theft of cookies, session tokens, or other sensitive information, or to perform actions on behalf of the victim within the affected web application.
Mitigation
Fixed versions are available: Apache HTTP Server 1.3.35, 2.0.58, and 2.2.2; IBM HTTP Server 6.0.2.13 and 6.1.0.1. Users should upgrade to these versions. As a workaround, it may be possible to block requests with Expect headers using a reverse proxy or web application firewall [1][2][3][4].
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
8cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:6.10:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:7.04:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:7.10:*:*:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server:2.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_workstation:2.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
56- secunia.com/advisories/21172nvdNot ApplicablePatchVendor Advisory
- secunia.com/advisories/21174nvdNot ApplicablePatchVendor Advisory
- archives.neohapsis.com/archives/bugtraq/2006-05/0151.htmlnvdBroken LinkExploit
- archives.neohapsis.com/archives/bugtraq/2006-07/0425.htmlnvdBroken LinkExploit
- securityreason.com/securityalert/1294nvdExploitThird Party Advisory
- svn.apache.org/viewvcnvdExploitVendor Advisory
- kb.vmware.com/KanisaPlatform/Publishing/466/5915871_f.SAL_Public.htmlnvdThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2008-04/msg00004.htmlnvdMailing ListThird Party Advisory
- marc.infonvdIssue TrackingMailing ListThird Party Advisory
- marc.infonvdIssue TrackingMailing ListThird Party Advisory
- marc.infonvdIssue TrackingMailing ListThird Party Advisory
- openbsd.org/errata.htmlnvdThird Party Advisory
- rhn.redhat.com/errata/RHSA-2006-0618.htmlnvdThird Party Advisory
- rhn.redhat.com/errata/RHSA-2006-0692.htmlnvdThird Party Advisory
- securitytracker.com/idnvdBroken LinkThird Party AdvisoryVDB Entry
- support.avaya.com/elmodocs2/security/ASA-2006-194.htmnvdThird Party Advisory
- www-1.ibm.com/support/docview.wssnvdThird Party Advisory
- www-1.ibm.com/support/docview.wssnvdThird Party Advisory
- www.debian.org/security/2006/dsa-1167nvdThird Party Advisory
- www.f-secure.com/en_EMEA/support/security-advisory/fsc-2010-2.htmlnvdThird Party Advisory
- www.novell.com/linux/security/advisories/2006_51_apache.htmlnvdThird Party Advisory
- www.redhat.com/support/errata/RHSA-2006-0619.htmlnvdThird Party Advisory
- www.securityfocus.com/bid/19661nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/idnvdBroken LinkThird Party AdvisoryVDB Entry
- www.ubuntu.com/usn/usn-575-1nvdThird Party Advisory
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10352nvdThird Party Advisory
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12238nvdThird Party Advisory
- patches.sgi.com/support/free/security/advisories/20060801-01-PnvdBroken Link
- secunia.com/advisories/21399nvdNot Applicable
- secunia.com/advisories/21478nvdNot Applicable
- secunia.com/advisories/21598nvdNot Applicable
- secunia.com/advisories/21744nvdNot Applicable
- secunia.com/advisories/21848nvdNot Applicable
- secunia.com/advisories/21986nvdNot Applicable
- secunia.com/advisories/22140nvdNot Applicable
- secunia.com/advisories/22317nvdNot Applicable
- secunia.com/advisories/22523nvdNot Applicable
- secunia.com/advisories/28749nvdNot Applicable
- secunia.com/advisories/29640nvdNot Applicable
- secunia.com/advisories/40256nvdNot Applicable
- www.vupen.com/english/advisories/2006/2963nvdPermissions Required
- www.vupen.com/english/advisories/2006/2964nvdPermissions Required
- www.vupen.com/english/advisories/2006/3264nvdPermissions Required
- www.vupen.com/english/advisories/2006/4207nvdPermissions Required
- www.vupen.com/english/advisories/2006/5089nvdPermissions Required
- www.vupen.com/english/advisories/2010/1572nvdPermissions Required
- www14.software.ibm.com/webapp/set2/subscriptions/pqvcmjdnvdBroken Link
- lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3Envd
- lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3Envd
- lists.apache.org/thread.html/r652fc951306cdeca5a276e2021a34878a76695a9f3cfb6490b4a6840%40%3Ccvs.httpd.apache.org%3Envd
- lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Envd
- lists.apache.org/thread.html/rafd145ba6cd0a4ced113a5823cdaff45aeb36eb09855b216401c66d6%40%3Ccvs.httpd.apache.org%3Envd
- lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3Envd
- lists.apache.org/thread.html/reb542d2038e9c331506e0cbff881b47e40fbe2bd93ff00979e60cdf7%40%3Ccvs.httpd.apache.org%3Envd
- lists.apache.org/thread.html/rf2f0f3611f937cf6cfb3b4fe4a67f69885855126110e1e3f2fb2728e%40%3Ccvs.httpd.apache.org%3Envd
- lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Envd
News mentions
0No linked articles in our index yet.