Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2007-6203

70
FAUCET Score

CVE-2007-6203 describes a cross-site scripting (XSS) vulnerability in Apache HTTP Server versions 2.0.x and 2.2.x. This flaw occurs because the server fails to properly sanitize the HTTP Method specifier header when reflecting it in a "413 Request Entity Too Large" error message. An attacker could exploit this by sending a crafted HTTP request with an invalid Content-length, potentially injecting malicious script into a user's browser. The vulnerability has a CVSS score of 4.3 (Medium severity), indicating a network-based attack with medium complexity and a partial impact on integrity. Its EPSS score of 0.731 suggests a higher-than-average probability of exploitation compared to other CVEs, and it has a high FAUCET Risk Score of 98/100. While not listed on the KEV catalog or Hot List, an exploit for this vulnerability is available on ExploitDB (EDB-30835). There is no evidence of active exploitation, and it has received minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
2.0.46CPE matchmatch criteria
cpe:2.3:a:apache:http_server:2.0.46:*:*:*:*:*:*:*
2.0.47CPE matchmatch criteria
cpe:2.3:a:apache:http_server:2.0.47:*:*:*:*:*:*:*
2.0.48CPE matchmatch criteria
cpe:2.3:a:apache:http_server:2.0.48:*:*:*:*:*:*:*
2.0.49CPE matchmatch criteria
cpe:2.3:a:apache:http_server:2.0.49:*:*:*:*:*:*:*
2.0.50CPE matchmatch criteria
cpe:2.3:a:apache:http_server:2.0.50:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

4.3MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N

Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
80.75%
Probability of exploitation in next 30 days
EPSS Percentile
99.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
ExploitDB: EDB-30835 · Nov 30, 2007
This CVE's current EPSS score of 0.8075 is in the 100th percentile among its peer group of 19,958 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2007-6203

httpd: Garbage before http method name is not escaped in a reply in case of errorneous request

Nov 30, 2007

References

docs.info.apple.com / article.html
lists.apple.com / archives/security-announce/2008/Mar/msg00001.html
lists.opensuse.org / opensuse-security-announce/2008-04/msg00004.html
marc.info
marc.info
procheckup.com / Vulnerability_PR07-37.php
Exploit
secunia.com / advisories/27906
Vendor Advisory
secunia.com / advisories/28196
Vendor Advisory
secunia.com / advisories/29348
Vendor Advisory
secunia.com / advisories/29420
Vendor Advisory
secunia.com / advisories/29640
Vendor Advisory
secunia.com / advisories/30356
Vendor Advisory
secunia.com / advisories/30732
Vendor Advisory
secunia.com / advisories/33105
Vendor Advisory
secunia.com / advisories/34219
Vendor Advisory
security.gentoo.org / glsa/glsa-200803-19.xml
securityreason.com / securityalert/3411
exchange.xforce.ibmcloud.com / vulnerabilities/38800
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12166
www-1.ibm.com / support/docview.wss
www-1.ibm.com / support/docview.wss
fujitsu.com / global/support/software/security/products-f/interstage-200807e.html
securityfocus.com / archive/1/484410/100/0/threaded
securityfocus.com / bid/26663
Exploit
securitytracker.com / id
ubuntu.com / usn/USN-731-1
vupen.com / english/advisories/2007/4060
vupen.com / english/advisories/2007/4301
vupen.com / english/advisories/2008/0924/references
vupen.com / english/advisories/2008/1623/references
vupen.com / english/advisories/2008/1875/references