Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2008-2939

32
FAUCET Score

CVE-2008-2939 describes a cross-site scripting (XSS) vulnerability in the mod_proxy_ftp module of Apache 2.0.63 and earlier, and Apache 2.2.9 and earlier 2.2 versions, also affecting products from Apple, Canonical, and OpenSUSE. This medium-severity vulnerability (CVSS 4.3) allows remote attackers to inject arbitrary web script or HTML by manipulating the pathname in an FTP URI. While it has a high FAUCET Risk Score of 97/100, there is no evidence of active exploitation, no known exploit code in Metasploit, Nuclei, or ExploitDB, and minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
<= 2.0.63CPE matchmatch criteria
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*
>= 2.2.0, <= 2.2.9CPE matchmatch criteria
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*
<= 10.5.6CPE matchmatch criteria
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
6.06CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:lts:*:*:*
7.10CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:7.10:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

4.3MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N

Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
38.95%
Probability of exploitation in next 30 days
EPSS Percentile
98.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.3895 is in the 99th percentile among its peer group of 19,958 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (24)

redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: ant-0:1.6.5-1jpp_1rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: avalon-logkit-0:1.2-2jpp_4rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: axis-0:1.2.1-1jpp_3rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: classpathx-jaf-0:1.0-2jpp_6rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: classpathx-mail-0:1.1.1-2jpp_8rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: geronimo-specs-0:1.0-0.M4.1jpp_10rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: jakarta-commons-modeler-0:2.0-3jpp_2rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: log4j-0:1.2.12-1jpp_1rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: mx4j-1:3.0.1-1jpp_4rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: pcsc-lite-0:1.3.3-3.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-ca-0:7.3.0-20.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-java-tools-0:7.3.0-10.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-kra-0:7.3.0-14.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-manage-0:7.3.0-19.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-native-tools-0:7.3.0-6.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-ocsp-0:7.3.0-13.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-tks-0:7.3.0-13.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: tomcat5-0:5.5.23-0jpp_4rh.16
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: xerces-j2-0:2.7.1-1jpp_1rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: xml-commons-0:1.3.02-2jpp_1rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: httpd-0:2.0.46-71.ent
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: httpd-0:2.0.52-41.ent.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: httpd-0:2.2.3-11.el5_2.4
View patch
redhatend of lifevia redhat_api
Product: Red Hat Directory Server 8Fixed in: httpd

Vendor Advisories (1)

redhatCVE-2008-2939Low

httpd: mod_proxy_ftp globbing XSS

Aug 5, 2008

References

lists.apple.com / archives/security-announce/2009/May/msg00002.html
Mailing List
lists.opensuse.org / opensuse-security-announce/2008-11/msg00000.html
Third Party Advisory
marc.info
Third Party Advisory
marc.info
Third Party Advisory
rhn.redhat.com / errata/RHSA-2008-0967.html
Third Party Advisory
secunia.com / advisories/31384
Broken Link
secunia.com / advisories/31673
Broken Link
secunia.com / advisories/32685
Broken Link
secunia.com / advisories/32838
Broken Link
secunia.com / advisories/33156
Broken Link
secunia.com / advisories/33797
Broken Link
secunia.com / advisories/34219
Broken Link
secunia.com / advisories/35074
Broken Link
exchange.xforce.ibmcloud.com / vulnerabilities/44223
VDB Entry
lists.apache.org / thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E
Third Party Advisory
lists.apache.org / thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E
Third Party Advisory
lists.apache.org / thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E
Third Party Advisory
lists.apache.org / thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E
Third Party Advisory
lists.apache.org / thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E
Third Party Advisory
lists.apache.org / thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E
Third Party Advisory
lists.apache.org / thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E
Third Party Advisory
lists.apache.org / thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E
Third Party Advisory
lists.apache.org / thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E
Third Party Advisory
lists.apache.org / thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3E
Third Party Advisory
lists.apache.org / thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3E
Third Party Advisory
lists.apache.org / thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E
Third Party Advisory
lists.apache.org / thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E
Third Party Advisory
lists.apache.org / thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E
Third Party Advisory
lists.apache.org / thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E
Third Party Advisory
lists.apache.org / thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E
Third Party Advisory
lists.apache.org / thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3E
Third Party Advisory
lists.apache.org / thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E
Third Party Advisory
lists.apache.org / thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E
Third Party Advisory
lists.apache.org / thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E
Third Party Advisory
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11316
Broken Link
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7716
Broken Link
sunsolve.sun.com / search/document.do
Broken Link
support.apple.com / kb/HT3549
Third Party Advisory
svn.apache.org / viewvc
Third Party Advisory
svn.apache.org / viewvc
Third Party Advisory
svn.apache.org / viewvc
Third Party Advisory
wiki.rpath.com / Advisories:rPSA-2008-0327
Broken Link
wiki.rpath.com / wiki/Advisories:rPSA-2008-0328
Broken Link
www-1.ibm.com / support/docview.wss
Third Party Advisory
www-1.ibm.com / support/docview.wss
Third Party Advisory
kb.cert.org / vuls/id/663763
Third Party AdvisoryUS Government Resource
mandriva.com / security/advisories
Broken Link
mandriva.com / security/advisories
Broken Link
mandriva.com / security/advisories
Broken Link
rapid7.com / advisories/R7-0033
Broken Link
redhat.com / support/errata/RHSA-2008-0966.html
Third Party Advisory
securityfocus.com / archive/1/495180/100/0/threaded
Third Party AdvisoryVDB Entry
securityfocus.com / archive/1/498566/100/0/threaded
Third Party AdvisoryVDB Entry
securityfocus.com / archive/1/498567/100/0/threaded
Third Party AdvisoryVDB Entry
securityfocus.com / bid/30560
Third Party AdvisoryVDB Entry
securitytracker.com / id
Third Party AdvisoryVDB Entry
ubuntu.com / usn/USN-731-1
Third Party AdvisoryVDB Entry
us-cert.gov / cas/techalerts/TA09-133A.html
Third Party AdvisoryUS Government Resource
vupen.com / english/advisories/2008/2315
Permissions Required
vupen.com / english/advisories/2008/2461
Permissions Required
vupen.com / english/advisories/2009/0320
Permissions Required
vupen.com / english/advisories/2009/1297
Permissions Required