|
The mod_ssl authentication module is vulnerable to cross-site scripting, caused by improper filtering of server signature data. A remote attacker could create a specially-crafted URL request that would cause a malicious HTTP "Host:" header which would be executed within the security context of the hosting site in the victim's browser. The existance of this vulnerability is limited to configurations with both the 'UseCanonicalName' option turned off and wildcard DNS enabled.
|