CVE-2005-3352
Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 73.7%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 73.69% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- apache/http server
- Source
- secalert@redhat.com
References
- ftp://patches.sgi.com/support/free/security/advisories/20060101-01-UBroken Link
- http://docs.info.apple.com/article.html?artnum=307562Broken Link
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01428449Broken Link
- http://issues.apache.org/bugzilla/show_bug.cgi?id=37874Issue Tracking
- http://lists.apple.com/archives/security-announce/2008//May/msg00001.htmlMailing List
- http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.htmlMailing List
- http://lists.suse.com/archive/suse-security-announce/2007-May/0005.htmlBroken Link
- http://lists.suse.de/archive/suse-security-announce/2006-Feb/0008.htmlBroken Link
- http://marc.info/?l=bugtraq&m=130497311408250&w=2Mailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2006-0159.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2006-0692.htmlBroken Link
- http://secunia.com/advisories/17319Not Applicable, URL Repurposed
- http://secunia.com/advisories/18008Not Applicable
- http://secunia.com/advisories/18333Not Applicable
- http://secunia.com/advisories/18339Not Applicable
- http://secunia.com/advisories/18340Not Applicable
- http://secunia.com/advisories/18429Not Applicable
- http://secunia.com/advisories/18517Not Applicable
- http://secunia.com/advisories/18526Not Applicable
- http://secunia.com/advisories/18585Not Applicable
- http://secunia.com/advisories/18743Not Applicable
- http://secunia.com/advisories/19012Not Applicable
- http://secunia.com/advisories/20046Not Applicable
- http://secunia.com/advisories/20670Not Applicable
- http://secunia.com/advisories/21744Not Applicable, Third Party Advisory
- http://secunia.com/advisories/22140Third Party Advisory
- http://secunia.com/advisories/22368Third Party Advisory
- http://secunia.com/advisories/22388Third Party Advisory
- http://secunia.com/advisories/22669Third Party Advisory
- http://secunia.com/advisories/23260Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.