S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2019-10092 Scanner

CVE-2019-10092 scanner - Cross-Site Scripting (XSS) vulnerability in Apache HTTP Server

Est. Time~30 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.7k
Times Used
continuous scan runs
4.3k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-10092
6.1
CVSS

In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of their choice. This would only be exploitable where a server was set up with proxying enabled but was misconfigured in such a way that the Proxy Error page was displayed.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Apache HTTP Serverby n/a
2.4.0 to 2.4.39
Updated Aug 21, 2026View on NVD →
Detail

Apache HTTP Server is a popular web server software that is used to deliver websites to end users. It is an open-source, cross-platform tool that is widely used in the industry due to its reliability and flexibility. Apache HTTP Server can be used to host various web applications and provide HTTP services to clients. This server software is extensively used by businesses of all sizes and web developers for managing web servers.

CVE-2019-10092 is a Cross-Site Scripting vulnerability that has been detected in Apache HTTP Server. This vulnerability permits attackers to manipulate the mod_proxy error page, thus causing the link to be malformed and directing the user to a page of their choice. The attack is only applicable in a misconfigured setting of the Proxy Error page. Therefore, attackers can use this vulnerability to trick users into believing that a legitimate website is being accessed, whereas they are being redirected to a malicious one.

Exploitation of CVE-2019-10092 carries serious consequences that can expose users to different cyber security risks. Through this vulnerability, the attacker can gain unauthorized access to sensitive data, including login credentials, personal information, business secrets, and more. Additionally, users may be prompted to execute malicious scripts, leading to malware installations that can conduct cyber espionage, steal data, or disrupt the normal functioning of a system.

In conclusion, security is an ongoing process that requires ongoing vigilance to ensure that your digital assets remain protected against evolving threats. With the pro features of the s4e.io platform, individuals and organizations can quickly and easily stay up-to-date with the latest vulnerabilities in their digital assets and take action to mitigate risks. By leveraging these tools, users can better protect themselves against the CVE-2019-10092 vulnerability and other online threats, ultimately providing a safer and more secure online experience.

 

REFERENCES

Solution Advice

To protect against this vulnerability, there are several precautionary measures that individuals and organizations can undertake, such as:

  • Update the Apache HTTP Server with the latest software version.
  • Configure the server to display detailed error messages to prevent attackers from exploiting the error pages.
  • Implement content security policy mechanisms, which can control and restrict the loading of scripts on web pages.
  • Enforce best practices in web application development, such as using secure and validated inputs in applications.
  • Deploy a Web Application Firewall (WAF) that can filter incoming traffic and block malicious requests.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-10092 scanner - Cross-Site Scripting (XSS) vulnerability in Apache HTTP Server | S4E