CVE-2007-6203 describes a cross-site scripting (XSS) vulnerability in Apache HTTP Server versions 2.0.x and 2.2.x. This flaw occurs because the server fails to properly sanitize the HTTP Method specifier header when reflecting it in a "413 Request Entity Too Large" error message. An attacker could exploit this by sending a crafted HTTP request with an invalid Content-length, potentially injecting malicious script into a user's browser. The vulnerability has a CVSS score of 4.3 (Medium severity), indicating a network-based attack with medium complexity and a partial impact on integrity. Its EPSS score of 0.731 suggests a higher-than-average probability of exploitation compared to other CVEs, and it has a high FAUCET Risk Score of 98/100. While not listed on the KEV catalog or Hot List, an exploit for this vulnerability is available on ExploitDB (EDB-30835). There is no evidence of active exploitation, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.46CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.0.46:*:*:*:*:*:*:* | ||
2.0.47CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.0.47:*:*:*:*:*:*:* | ||
2.0.48CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.0.48:*:*:*:*:*:*:* | ||
2.0.49CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.0.49:*:*:*:*:*:*:* | ||
2.0.50CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.0.50:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.