CVE-2007-5000
medium · 4.3Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2) mod_imagemap module in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
4.3
CVSS
46.6%
EPSS (exploit prob.)
99th
EPSS percentile
2007-12-13
Published
AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
CWE-79
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | http_server | >= 1.3.0, <= 1.3.39 |
| apache | http_server | >= 2.0.35, <= 2.0.61 |
| apache | http_server | >= 2.2.0, <= 2.2.6 |
| fedoraproject | fedora | 7 |
| fedoraproject | fedora | 8 |
| canonical | ubuntu_linux | 6.06 |
| canonical | ubuntu_linux | 6.10 |
| canonical | ubuntu_linux | 7.04 |
| canonical | ubuntu_linux | 7.10 |
| opensuse | opensuse | 10.2 |
| opensuse | opensuse | 10.3 |
| suse | linux_enterprise_desktop | 9 |
| suse | linux_enterprise_server | 9 |
| suse | linux_enterprise_server | 10 |
| oracle | http_server | 10.1.3.5.0 |
Check a specific version with /api/v1/cve/match.
References
- http://docs.info.apple.com/article.html?artnum=307562
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01345501
- http://httpd.apache.org/security/vulnerabilities_13.html
- http://httpd.apache.org/security/vulnerabilities_20.html
- http://httpd.apache.org/security/vulnerabilities_22.html
- http://lists.apple.com/archives/security-announce/2008//May/msg00001.html
- http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2008-04/msg00004.html
- http://lists.vmware.com/pipermail/security-announce/2009/000062.html
- http://marc.info/?l=bugtraq&m=130497311408250&w=2
- http://secunia.com/advisories/28046
- http://secunia.com/advisories/28073
- http://secunia.com/advisories/28081
- http://secunia.com/advisories/28196
- http://secunia.com/advisories/28375
- http://secunia.com/advisories/28467
- http://secunia.com/advisories/28471
- http://secunia.com/advisories/28525
- http://secunia.com/advisories/28526
- http://secunia.com/advisories/28607
- http://secunia.com/advisories/28749
- http://secunia.com/advisories/28750
- http://secunia.com/advisories/28922
- http://secunia.com/advisories/28977
- http://secunia.com/advisories/29420
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2007-5000