date=2023-08-01
time=01:27:30
srcip=185.130.92.100
attack=Apache.Expect.Header.XSS
srcport=43127 ...
show moredate=2023-08-01
time=01:27:30
srcip=185.130.92.100
attack=Apache.Expect.Header.XSS
srcport=43127
dstport=443
show less
date=2023-05-23
time=01:29:38
srcip=185.130.92.100
attack="Apache.Expect.Header.XSS"
srcport= ...
show moredate=2023-05-23
time=01:29:38
srcip=185.130.92.100
attack="Apache.Expect.Header.XSS"
srcport=9786
dstport=443
show less
date=2023-01-10
time=01:32:56
srcip=185.130.92.100
attack="Apache.Expect.Header.XSS"
srcport=531 ...
show moredate=2023-01-10
time=01:32:56
srcip=185.130.92.100
attack="Apache.Expect.Header.XSS"
srcport=53139
dstport=443
show less
date=2022-04-04
time=23:55:59
srcip=185.130.92.100
srccountry="United Kingdom"
attack="Apache.Ex ...
show moredate=2022-04-04
time=23:55:59
srcip=185.130.92.100
srccountry="United Kingdom"
attack="Apache.Expect.Header.XSS"
srcport=47104
dstport=443
date=2022-04-05
time=01:29:02
srcip=185.130.92.100
srccountry="United Kingdom"
attack="Apache.Expect.Header.XSS"
srcport=35182
dstport=443
Apache.Expect.Header.XSS
Description
This indicates an attempt to exploit a cross site scripting (XSS) vulnerability in Apache HTTP Server.
The vulnerability is caused by an error that occurs when the vulnerable software handles a malicious "Expect" header. It can be exploited to launch cross site scripting attacks using web client components that can send arbitrary headers in requests.
Affected Products
Apache versions prior to 1.3.35
Apache versions prior to 2.0.58
Apache versions prior to 2.2.2
Impact
System compromise: cross site scripting.
Recommended Actions
Apply the latest update from the vendor
http://httpd.apache.org/
show less
Hacking
Web App Attack
Showing 1 to
6
of 6 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ