← Vulnerability feed

Vulnerability record · CVE-2002-0840 · published 11 October 2002

CVE-2002-0840: Apache HTTP Server default error page XSS via Host header

Apache · Http Server

Apache 2.0 before 2.0.43 and 1.3.x up to 1.3.26 reflect the Host header into the default error page when UseCanonicalName is Off and wildcard DNS is in use, allowing script injection. The flaw is a cross-site scripting issue distinct from CAN-2002-1157, and it matters because any visitor who reaches an error page can be served attacker-controlled script in the server's origin.

6.8 CVSS 2.0 Medium EPSS 95% · top 0.1%
6.8CVSS 2.0 base score
95%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
74References
16 Jun 2026Last modified by NVD

Description

Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors via the Host: header, a different vulnerability than CAN-2002-1157.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityThe flaw is remotely reachable and reflected XSS in a widely deployed web server, and EPSS is near the top of the distribution, though it is not in KEV and requires specific configuration and victim interaction.

What it is

Apache 2.0 before 2.0.43 and 1.3.x up to 1.3.26 reflect the Host header into the default error page when UseCanonicalName is Off and wildcard DNS is in use, allowing script injection. The flaw is a cross-site scripting issue distinct from CAN-2002-1157, and it matters because any visitor who reaches an error page can be served attacker-controlled script in the server's origin.

Impact

An attacker can execute script in the browser of other visitors to the affected site, enabling session theft, credential capture or redirection within the site's trust context.

Attack surface

Reached remotely over HTTP by sending a crafted Host header to a server configured with UseCanonicalName Off and wildcard DNS; no authentication is required, but the victim must load the resulting error page, so some user interaction is implied.

Exploitation

Not listed in CISA KEV and no ransomware use is documented; EPSS is very high (0.95087, 99.859th percentile), and references are vendor advisories and distro errata rather than public exploit tags.

What to do

  • Upgrade Apache to 2.0.43 or later, or the fixed 1.3.x release, and apply the linked vendor errata for Oracle, Red Hat, Debian and Mandrake packages.
  • Set UseCanonicalName to On where operationally possible to stop the Host header being reflected.
  • Disable wildcard DNS for the affected virtual hosts so arbitrary Host values do not resolve to the server.
  • Replace or customize default error pages so request headers are not echoed into responses.
  • Encode or reject untrusted Host header values at the reverse proxy or web server layer.

Detection

  • Search web server access and error logs for Host header values containing script tags, angle brackets or encoded HTML entities.
  • Monitor for requests that trigger error responses (4xx/5xx) with unusual Host values from the same source.
  • Review error page responses for reflected Host header content using an HTTP proxy or scanner.
  • Alert on configuration drift where UseCanonicalName is set to Off on internet-facing Apache instances.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
ftp://patches.sgi.com/support/free/security/advisories/20021105-02-I
http://archives.neohapsis.com/archives/bugtraq/2002-10/0254.html
http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0003.html
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000530
http://marc.info/?l=apache-httpd-announce&m=103367938230488&w=2
http://marc.info/?l=bugtraq&m=103357160425708&w=2
http://marc.info/?l=bugtraq&m=103376585508776&w=2
http://online.securityfocus.com/advisories/4617
http://www.apacheweek.com/issues/02-10-04 Vendor Advisory
http://www.debian.org/security/2002/dsa-187
http://www.debian.org/security/2002/dsa-188
http://www.debian.org/security/2002/dsa-195
http://www.kb.cert.org/vuls/id/240329 US Government Resource
http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-068.php
http://www.linuxsecurity.com/advisories/other_advisory-2414.html
http://www.osvdb.org/862
http://www.redhat.com/support/errata/RHSA-2002-222.html
http://www.redhat.com/support/errata/RHSA-2002-243.html
http://www.redhat.com/support/errata/RHSA-2002-244.html
http://www.redhat.com/support/errata/RHSA-2002-248.html
http://www.redhat.com/support/errata/RHSA-2002-251.html
http://www.redhat.com/support/errata/RHSA-2003-106.html
http://www.securityfocus.com/bid/5847
https://exchange.xforce.ibmcloud.com/vulnerabilities/10241
https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%
https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%
https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/r5001ecf3d6b2bdd0b732e527654248abb264f08390045d30709a92f6%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/rd00b45b93fda4a5bd013b28587207d0e00f99f6e3308dbb6025f3b01%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/rf2f0f3611f937cf6cfb3b4fe4a67f69885855126110e1e3f2fb2728e%40%3Ccvs.httpd.apache.org
https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org
ftp://patches.sgi.com/support/free/security/advisories/20021105-02-I
http://archives.neohapsis.com/archives/bugtraq/2002-10/0254.html
http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0003.html

Track CVE-2002-0840 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-42013Apache HTTP Server path traversal and RCE via incomplete fixThe fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient, leaving a path traversal flaw that lets attackers map URLs to files outside…KEVEPSS 100%analysed9.8CVE-2021-41773Apache HTTP Server 2.4.49 path traversal and RCEA path normalization flaw introduced in Apache HTTP Server 2.4.49 lets attackers map URLs to files outside directories configured by Alias-like direc…KEVEPSS 100%analysed9.1CVE-2024-38475Apache HTTP Server mod_rewrite improper escaping enables code executionApache HTTP Server 2.4.59 and earlier has an improper output escaping flaw in mod_rewrite. Substitutions in server context that use a backreference o…KEVEPSS 100%analysed9.0CVE-2021-40438Apache HTTP Server mod_proxy SSRF via crafted URI pathA crafted request URI path can make mod_proxy forward the request to an origin server chosen by the remote user, an SSRF flaw in Apache HTTP Server 2…KEVEPSS 100%analysed7.8CVE-2019-0211Apache HTTP Server scoreboard use-after-free local privilege escalationApache HTTP Server 2.4.17 through 2.4.38 with MPM event, worker or prefork contains a use-after-free in scoreboard handling. Code running in a less-p…KEVEPSS 65%analysed10.0CVE-2020-1953Apache commons configuration vulnerabilityApache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes…EPSS 6.8%10.0CVE-2015-4863Oracle database server vulnerabilityUnspecified vulnerability in the Portable Clusterware component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote attackers to…EPSS 3.1%10.0CVE-2013-1534Oracle database server vulnerabilityUnspecified vulnerability in the Workload Manager component in Oracle Database Server 11.2.0.2 and 11.2.0.3, when used in RAC configurations, allows …EPSS 3.7%

Source: NIST National Vulnerability Database (record CVE-2002-0840), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.