CVE-2007-5000
Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2) mod_imagemap module in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 46.6%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2) mod_imagemap module in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 46.60% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- apache/http server · fedoraproject/fedora · canonical/ubuntu linux · opensuse/opensuse · suse/linux enterprise desktop · suse/linux enterprise server · oracle/http server
- Source
- secalert@redhat.com
References
- http://docs.info.apple.com/article.html?artnum=307562Broken Link
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01345501Broken Link
- http://httpd.apache.org/security/vulnerabilities_13.htmlVendor Advisory
- http://httpd.apache.org/security/vulnerabilities_20.htmlVendor Advisory
- http://httpd.apache.org/security/vulnerabilities_22.htmlVendor Advisory
- http://lists.apple.com/archives/security-announce/2008//May/msg00001.htmlBroken Link, Mailing List, Third Party Advisory
- http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.htmlBroken Link, Mailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00004.htmlMailing List, Third Party Advisory
- http://lists.vmware.com/pipermail/security-announce/2009/000062.htmlMailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=130497311408250&w=2Issue Tracking, Third Party Advisory
- http://secunia.com/advisories/28046Broken Link, Vendor Advisory
- http://secunia.com/advisories/28073Broken Link, Vendor Advisory
- http://secunia.com/advisories/28081Broken Link
- http://secunia.com/advisories/28196Broken Link
- http://secunia.com/advisories/28375Broken Link
- http://secunia.com/advisories/28467Broken Link
- http://secunia.com/advisories/28471Broken Link
- http://secunia.com/advisories/28525Broken Link
- http://secunia.com/advisories/28526Broken Link
- http://secunia.com/advisories/28607Broken Link
- http://secunia.com/advisories/28749Broken Link
- http://secunia.com/advisories/28750Broken Link
- http://secunia.com/advisories/28922Broken Link
- http://secunia.com/advisories/28977Broken Link
- http://secunia.com/advisories/29420Broken Link
- http://secunia.com/advisories/29640Broken Link
- http://secunia.com/advisories/29806Broken Link
- http://secunia.com/advisories/29988Broken Link
- http://secunia.com/advisories/30356Broken Link
- http://secunia.com/advisories/30430Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.