CVE-2002-0840 describes a cross-site scripting (XSS) vulnerability in Apache 1.3.x (up to 1.3.26) and 2.0 (before 2.0.43) web servers. This flaw occurs in the default error page when UseCanonicalName is "Off" and wildcard DNS is enabled, allowing remote attackers to inject and execute scripts in a victim's browser via a manipulated Host header. With a CVSS score of 6.8, this vulnerability is considered medium severity, requiring medium attack complexity but potentially leading to partial confidentiality, integrity, and availability impacts. While not listed in CISA's KEV catalog, an ExploitDB entry (EDB-21885) exists, indicating public exploit code availability, despite minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.3CPE matchmatch criteria | cpe:2.3:a:apache:http_server:1.3:*:*:*:*:*:*:* | ||
1.3.1CPE matchmatch criteria | cpe:2.3:a:apache:http_server:1.3.1:*:*:*:*:*:*:* | ||
1.3.3CPE matchmatch criteria | cpe:2.3:a:apache:http_server:1.3.3:*:*:*:*:*:*:* | ||
1.3.4CPE matchmatch criteria | cpe:2.3:a:apache:http_server:1.3.4:*:*:*:*:*:*:* | ||
1.3.6CPE matchmatch criteria | cpe:2.3:a:apache:http_server:1.3.6:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.