This script is Copyright (C) 2011-2016 Tenable Network Security, Inc.
The remote web server may be affected by one or more issues.
According to its banner, the version of Apache running on the remote
host does not properly escape filenames in 406 responses. A remote
attacker can exploit this to inject arbitrary HTTP headers or conduct
cross-site scripting attacks by uploading a file with a specially
Note that the remote web server may not actually be affected by these
vulnerabilities as Nessus has relied solely on the version number in
the server's banner.
See also :
Upgrade to Apache 2.3.2 or later. Alternatively, apply the workaround
referenced in the vendor advisory.
Risk factor :
Medium / CVSS Base Score : 4.3
CVSS Temporal Score : 3.7
Public Exploit Available : false