CVE-2008-2939

Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web script or HTML via a wildcard in the last directory component in the pathname in an FTP URI.

Published: 2008-08-06 Last update: 2026-04-23 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2008-2939 is rated Moderate Risk (46.7/100): CVSS Medium severity, with high exploitation likelihood (EPSS 64.56%, 98th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2008-2939

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-04-07 71.25% 64.56% -6.69%
2 2026-03-04 33.52% 71.25% +37.73%
3 2026-03-01 33.52%

Full EPSS history (55 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2008-2939

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
4.3 2.0 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:N)
No confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:N)
No availability impact.
8.6 2.9 [email protected]

Weakness enumeration for CVE-2008-2939

OS Trackers for CVE-2008-2939

vendor priority summary link
debian low CVE-2008-2939 low priority: Debian including 1 source packages (apache2), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2008-2939
redhat low https://access.redhat.com/security/cve/CVE-2008-2939
suse medium CVE-2008-2939 severity moderate: SUSE including 33 source package names (apache2-2.2.10-2.24.5, apache2-2.2.12-1.28.1, …), 39 product×package rows across 7 product lines (SUSE Linux Enterprise Server 11 SP1, SUSE Linux Enterprise Server 11 SP2, … (7 product lines)): Fixed 39. https://www.suse.com/security/cve/CVE-2008-2939/
ubuntu low CVE-2008-2939 low priority: Ubuntu including 2 source packages (apache, apache2), 12 status rows across 6 suites (dapper, feisty, gutsy, hardy, intrepid, upstream): not-affected 4, released 4, DNE 3, ignored 1. https://ubuntu.com/security/CVE-2008-2939

Vendor comments (NVD) for CVE-2008-2939

  • Red Hat (2008-11-12T00:00:00)

    These issue was addressed in all affected httpd versions as shipped in Red Hat Enterprise Linux 3, 4, and 5 were fixed via: https://rhn.redhat.com/errata/RHSA-2008-0967.html This issue is tracked via the following bug: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=CVE-2008-2939 The Red Hat Security Response Team has rated this issue as having low security impact, future updates may address this flaw in other affected products (such as Red Hat Application Stack).

Affected software / configurations for CVE-2008-2939

Vendor Product Version Raw CPE
apache http_server <= 2.0.63 cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*
apache http_server >= 2.2.0, <= 2.2.9 cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*
apple mac_os_x <= 10.5.6 cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
canonical ubuntu_linux 6.06 cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:lts:*:*:*
canonical ubuntu_linux 7.10 cpe:2.3:o:canonical:ubuntu_linux:7.10:*:*:*:*:*:*:*
canonical ubuntu_linux 8.04 cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:lts:*:*:*
opensuse opensuse 10.2 cpe:2.3:o:opensuse:opensuse:10.2:*:*:*:*:*:*:*
opensuse opensuse 10.3 cpe:2.3:o:opensuse:opensuse:10.3:*:*:*:*:*:*:*
opensuse opensuse 11.0 cpe:2.3:o:opensuse:opensuse:11.0:*:*:*:*:*:*:*

References for CVE-2008-2939

URL Tags
http://lists.apple.com/archives/security-announce/2009/May/msg00002.html Mailing List
http://lists.opensuse.org/opensuse-security-announce/2008-11/msg00000.html Third Party Advisory
http://marc.info/?l=bugtraq&m=123376588623823&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=125631037611762&w=2 Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2008-0967.html Third Party Advisory
http://secunia.com/advisories/31384 Broken Link
http://secunia.com/advisories/31673 Broken Link
http://secunia.com/advisories/32685 Broken Link
http://secunia.com/advisories/32838 Broken Link
http://secunia.com/advisories/33156 Broken Link
http://secunia.com/advisories/33797 Broken Link
http://secunia.com/advisories/34219 Broken Link
http://secunia.com/advisories/35074 Broken Link
http://sunsolve.sun.com/search/document.do?assetkey=1-26-247666-1 Broken Link
http://support.apple.com/kb/HT3549 Third Party Advisory
http://svn.apache.org/viewvc?view=rev&revision=682868 Third Party Advisory
http://svn.apache.org/viewvc?view=rev&revision=682870 Third Party Advisory
http://svn.apache.org/viewvc?view=rev&revision=682871 Third Party Advisory
http://wiki.rpath.com/Advisories:rPSA-2008-0327 Broken Link
http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0328 Broken Link
http://www-1.ibm.com/support/docview.wss?uid=swg1PK70197 Third Party Advisory
http://www-1.ibm.com/support/docview.wss?uid=swg1PK70937 Third Party Advisory
http://www.kb.cert.org/vuls/id/663763 Third Party Advisory US Government Resource
http://www.mandriva.com/security/advisories?name=MDVSA-2008:194 Broken Link
http://www.mandriva.com/security/advisories?name=MDVSA-2008:195 Broken Link
http://www.mandriva.com/security/advisories?name=MDVSA-2009:124 Broken Link
http://www.rapid7.com/advisories/R7-0033 Broken Link
http://www.redhat.com/support/errata/RHSA-2008-0966.html Third Party Advisory
http://www.securityfocus.com/archive/1/495180/100/0/threaded Third Party Advisory VDB Entry
http://www.securityfocus.com/archive/1/498566/100/0/threaded Third Party Advisory VDB Entry
http://www.securityfocus.com/archive/1/498567/100/0/threaded Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/30560 Third Party Advisory VDB Entry
http://www.securitytracker.com/id?1020635 Third Party Advisory VDB Entry
http://www.ubuntu.com/usn/USN-731-1 Third Party Advisory VDB Entry
http://www.us-cert.gov/cas/techalerts/TA09-133A.html Third Party Advisory US Government Resource
http://www.vupen.com/english/advisories/2008/2315 Permissions Required
http://www.vupen.com/english/advisories/2008/2461 Permissions Required
http://www.vupen.com/english/advisories/2009/0320 Permissions Required
http://www.vupen.com/english/advisories/2009/1297 Permissions Required
https://exchange.xforce.ibmcloud.com/vulnerabilities/44223 VDB Entry
https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E Third Party Advisory
https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E Third Party Advisory
https://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E Third Party Advisory
https://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E Third Party Advisory
https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E Third Party Advisory
https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E Third Party Advisory
https://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E Third Party Advisory
https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E Third Party Advisory
https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E Third Party Advisory
https://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3E Third Party Advisory
https://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3E Third Party Advisory
https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E Third Party Advisory
https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E Third Party Advisory
https://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E Third Party Advisory
https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E Third Party Advisory
https://lists.apache.org/thread.html/rb9c9f42dafa25d2f669dac2a536a03f2575bc5ec1be6f480618aee10%40%3Ccvs.httpd.apache.org%3E Third Party Advisory
https://lists.apache.org/thread.html/rc4c53a0d57b2771ecd4b965010580db355e38137c8711311ee1073a8%40%3Ccvs.httpd.apache.org%3E Third Party Advisory
https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E Third Party Advisory
https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E Third Party Advisory
https://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11316 Broken Link
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7716 Broken Link
cvelogic Threat Intelligence