paul Posted December 8, 2009 Report Share Posted December 8, 2009 A vulnerability has been found and corrected in mod_perl v1.x and v2.x: Cross-site scripting (XSS) vulnerability in Status.pm in Apache::Status and Apache2::Status in mod_perl1 and mod_perl2 for the Apache HTTP Server, when /perl-status is accessible, allows remote attackers to inject arbitrary web script or HTML via the URI (CVE-2009-0796). The updated packages have been patched to correct these issues. Update: Packages for 2008.0 are being provided due to extended support for Corporate products. Link to comment Share on other sites More sharing options...
Recommended Posts