CVE-2007-6203
Description
Apache HTTP Server 2.0.x and 2.2.x does not sanitize the HTTP Method specifier header from an HTTP request when it is reflected back in a "413 Request Entity Too Large" error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated via an HTTP request containing an invalid Content-length value, a similar issue to CVE-2006-3918.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Apache HTTP Server does not sanitize the HTTP method specifier header in '413 Request Entity Too Large' error responses, enabling XSS attacks.
Vulnerability
CVE-2007-6203 is a cross-site scripting (XSS) vulnerability in Apache HTTP Server versions 2.0.x and 2.2.x. The server fails to sanitize the HTTP method specifier header from a request when reflecting it back in a "413 Request Entity Too Large" error message. This behavior occurs when an invalid Content-Length header value triggers the error response [1][2][4]. The vulnerability is similar to CVE-2006-3918.
Exploitation
An attacker needs no authentication and can exploit this vulnerability remotely. The attack requires a user's browser or other web client components capable of sending arbitrary headers in HTTP requests. The attacker crafts an HTTP request with a malicious payload in the method specifier header and an invalid Content-Length value to trigger the 413 error. When the server reflects the payload in the error response, any user viewing that response in a browser may have the malicious script executed in the context of the vulnerable domain [2][4].
Impact
Successful exploitation results in reflected cross-site scripting. An attacker can inject arbitrary HTML or JavaScript into a victim's browser, potentially leading to session hijacking, cookie theft, defacement, or redirection to malicious sites. The impact is limited to the same-origin domain and requires social engineering to trick a user into viewing the crafted server response [1][4].
Mitigation
Patches are available from multiple vendors. IBM released PK65782 for IBM HTTP Server 2.0.47.1 [1]. HP provided updates for HP-UX Apache-based Web Server: versions before v2.2.8.05 (HP-UX B.11.23, B.11.31) and v2.0.59.12 (HP-UX B.11.11, B.11.23, B.11.31) [2]; later a fix was included in Apache-based Web Server v2.0.63.01 (Web Server Suite v2.32) [3]. Ubuntu included fixes in USN-731-1 for Ubuntu 6.06 LTS and 7.10 [4]. Users should upgrade to a fixed version or apply the appropriate patch. There is no known workaround for unpatched installations.
- PK65782; 2.0.47.1: IBM HTTP Server V2.0.47 Cumulative Interim Fix
- '[security bulletin] HPSBUX02465 SSRT090192 rev.1 - HP-UX Running Apache-based Web Server, Remote Den'
- '[security bulletin] HPSBUX02612 SSRT100345 rev.1 - HP-UX Apache-based Web Server, Local Information'
- USN-731-1: Apache vulnerabilities | Ubuntu security notices | Ubuntu
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
26cpe:2.3:a:apache:http_server:2.0.46:*:*:*:*:*:*:*+ 25 more
- cpe:2.3:a:apache:http_server:2.0.46:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.47:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.48:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.49:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.50:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.51:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.52:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.53:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.54:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.55:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.57:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.58:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.0.59:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.1.5:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.1.6:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.1.7:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.1.8:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:apache:http_server:2.2.4:*:*:*:*:*:*:*
- (no CPE)range: 2.0.x and 2.2.x
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
31- procheckup.com/Vulnerability_PR07-37.phpnvdExploit
- www.securityfocus.com/bid/26663nvdExploit
- secunia.com/advisories/27906nvdVendor Advisory
- secunia.com/advisories/28196nvdVendor Advisory
- secunia.com/advisories/29348nvdVendor Advisory
- secunia.com/advisories/29420nvdVendor Advisory
- secunia.com/advisories/29640nvdVendor Advisory
- secunia.com/advisories/30356nvdVendor Advisory
- secunia.com/advisories/30732nvdVendor Advisory
- secunia.com/advisories/33105nvdVendor Advisory
- secunia.com/advisories/34219nvdVendor Advisory
- docs.info.apple.com/article.htmlnvd
- lists.apple.com/archives/security-announce/2008/Mar/msg00001.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2008-04/msg00004.htmlnvd
- marc.infonvd
- marc.infonvd
- security.gentoo.org/glsa/glsa-200803-19.xmlnvd
- securityreason.com/securityalert/3411nvd
- www-1.ibm.com/support/docview.wssnvd
- www-1.ibm.com/support/docview.wssnvd
- www.fujitsu.com/global/support/software/security/products-f/interstage-200807e.htmlnvd
- www.securityfocus.com/archive/1/484410/100/0/threadednvd
- www.securitytracker.com/idnvd
- www.ubuntu.com/usn/USN-731-1nvd
- www.vupen.com/english/advisories/2007/4060nvd
- www.vupen.com/english/advisories/2007/4301nvd
- www.vupen.com/english/advisories/2008/0924/referencesnvd
- www.vupen.com/english/advisories/2008/1623/referencesnvd
- www.vupen.com/english/advisories/2008/1875/referencesnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/38800nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12166nvd
News mentions
0No linked articles in our index yet.