CVE-2005-3352
medium · 4.3Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.
4.3
CVSS
73.7%
EPSS (exploit prob.)
99th
EPSS percentile
2005-12-13
Published
AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
CWE-79
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | http_server | < 1.3.35 |
| apache | http_server | >= 2.0, < 2.0.56 |
| apache | http_server | 2.2 |
Check a specific version with /api/v1/cve/match.
References
- ftp://patches.sgi.com/support/free/security/advisories/20060101-01-U
- http://docs.info.apple.com/article.html?artnum=307562
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01428449
- http://issues.apache.org/bugzilla/show_bug.cgi?id=37874
- http://lists.apple.com/archives/security-announce/2008//May/msg00001.html
- http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html
- http://lists.suse.com/archive/suse-security-announce/2007-May/0005.html
- http://lists.suse.de/archive/suse-security-announce/2006-Feb/0008.html
- http://marc.info/?l=bugtraq&m=130497311408250&w=2
- http://rhn.redhat.com/errata/RHSA-2006-0159.html
- http://rhn.redhat.com/errata/RHSA-2006-0692.html
- http://secunia.com/advisories/17319
- http://secunia.com/advisories/18008
- http://secunia.com/advisories/18333
- http://secunia.com/advisories/18339
- http://secunia.com/advisories/18340
- http://secunia.com/advisories/18429
- http://secunia.com/advisories/18517
- http://secunia.com/advisories/18526
- http://secunia.com/advisories/18585
- http://secunia.com/advisories/18743
- http://secunia.com/advisories/19012
- http://secunia.com/advisories/20046
- http://secunia.com/advisories/20670
- http://secunia.com/advisories/21744
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2005-3352