VYPR
Unrated severityNVD Advisory· Published Dec 3, 2007· Updated Jun 16, 2026

CVE-2007-6203

CVE-2007-6203

Description

Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "413 Request Entity Too Large" error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated via an HTTP request containing an invalid Content-length value, a similar issue to CVE-2006-3918.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

26
  • Apache/HTTP Serverllm-fuzzy26 versions
    2.0.x, 2.2.x+ 25 more
    • (no CPE)range: 2.0.x, 2.2.x
    • cpe:2.3:a:apache:http_server:2.0.46:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.0.47:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.0.48:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.0.49:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.0.50:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.0.51:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.0.52:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.0.53:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.0.54:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.0.55:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.0.57:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.0.58:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.0.59:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.1.3:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.1.4:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.1.5:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.1.6:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.1.7:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.1.8:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.2.2:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.2.3:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:http_server:2.2.4:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

31

News mentions

0

No linked articles in our index yet.