CVE-2012-4001

The mod_pagespeed module before 0.10.22.6 for the Apache HTTP Server does not properly verify its host name, which allows remote attackers to trigger HTTP requests to arbitrary hosts via unspecified vectors, as demonstrated by requests to intranet servers.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:google:mod_pagespeed:0.10.19.1:*:*:*:*:*:*:*
cpe:2.3:a:google:mod_pagespeed:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*

Information

Published : 2012-09-15 03:37

Updated : 2018-10-30 09:26


NVD link : CVE-2012-4001

Mitre link : CVE-2012-4001


JSON object : View

CWE
CWE-20

Improper Input Validation

Advertisement

dedicated server usa

Products Affected

apache

  • http_server

google

  • mod_pagespeed