VYPR
Unrated severityNVD Advisory· Published Jan 12, 2008· Updated Apr 23, 2026

CVE-2008-0005

CVE-2008-0005

Description

mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 encoding.

Affected products

7
  • cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*
    Range: >=2.0.35,<2.0.63
  • cpe:2.3:o:fedoraproject:fedora:7:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fedoraproject:fedora:7:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:8:*:*:*:*:*:*:*
  • cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:6.10:*:*:*:*:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:7.04:*:*:*:*:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:7.10:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

62

News mentions

0

No linked articles in our index yet.