CVE-2007-4465

Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is not defined, allows remote attackers to inject arbitrary web script or HTML via the P parameter using the UTF-7 charset. NOTE: it could be argued that this issue is due to a design limitation of browsers that attempt to perform automatic content type detection.


We have discovered 129,029 live websites that are affected by CVE-2007-4465.

Run a Free Instant Scan




Affected Software

Product  Apache
Category Web Servers
Vulnerable Domains129,029 live websites (4.71% of Apache install base)
Vulnerable Versions
  • from 0 through 2.2.6
Vulnerable Versions Count32 versions ( 27% of all versions)



Details

  • Published - Sep 14, 2007
  • Updated - Jan 17, 2025

Website Distribution by Country

Number of websites using CVE-2007-4465
United States11,021 websites



Taiwan82,673 websites
Japan7,619 websites
Germany4,403 websites
France1,810 websites
Russia1,762 websites
Italy1,559 websites
Canada1,556 websites
Austria1,367 websites

Website Distribution by TLD

Number of websites using CVE-2007-4465
.com84,279 websites
.info4,618 websites
.net4,128 websites
.de3,481 websites
.org2,483 websites
.jp1,915 websites
.ru1,562 websites
.at1,117 websites
.it1,108 websites
.co.jp1,108 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2007-4465

Top websites that are affected by CVE-2007-4465. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.********.de Germany*,***
**********.com United States*,***
****.**********.com United States*,***
*****.**********.com United States*,***
*****.***.tw Taiwan*,***
*******.****************.com United States*,***
*******.**********.com United States*,***
***.************.de Germany*,***
******.****.br Brazil*,***
**********.***.com United States*,***
See full domain list

FAQ

A total of 129,029 websites have been identified as vulnerable to CVE-2007-4465, based on global website indexing conducted by WebTechSurvey.
The Apache is affected by the CVE-2007-4465 vulnerability.
Apache versions up to and including 2.2.6 are vulnerable to CVE-2007-4465.

References