Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is not defined, allows remote attackers to inject arbitrary web script or HTML via the P parameter using the UTF-7 charset. NOTE: it could be argued that this issue is due to a design limitation of browsers that attempt to perform automatic content type detection.
We have discovered 129,029 live websites that are affected by CVE-2007-4465.
| Product | |
| Category | Web Servers |
| Vulnerable Domains | 129,029 live websites (4.71% of Apache install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 32 versions ( 27% of all versions) |
| 11,021 websites | |
| 82,673 websites | |
| 7,619 websites | |
| 4,403 websites | |
| 1,810 websites | |
| 1,762 websites | |
| 1,559 websites | |
| 1,556 websites | |
| 1,367 websites | |
| .com | 84,279 websites |
| .info | 4,618 websites |
| .net | 4,128 websites |
| .de | 3,481 websites |
| .org | 2,483 websites |
| .jp | 1,915 websites |
| .ru | 1,562 websites |
| .at | 1,117 websites |
| .it | 1,108 websites |
| .co.jp | 1,108 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ********.********.de | *,*** | ||
| **********.com | *,*** | ||
| ****.**********.com | *,*** | ||
| *****.**********.com | *,*** | ||
| *****.***.tw | *,*** | ||
| *******.****************.com | *,*** | ||
| *******.**********.com | *,*** | ||
| ***.************.de | *,*** | ||
| ******.****.br | *,*** | ||
| **********.***.com | *,*** |