Back

CVE-2005-3352

Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.

Published: Dec 13, 2005 Modified: Jun 16, 2026
CWE-79

CVSS Metrics

Affected Products (3)

Vendor Product Version
apache http_server * < 1.3.35
apache http_server * ≥ 2.0 < 2.0.56
apache http_server 2.2

GitHub Security Advisory GHSA-3h5q-3j8q-4rm9

Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev...

Risk Scores

CVSS Score 4.3 / 10
EPSS Score 73.69%

Top 1% most likely to be exploited

Threat Score 49.3 / 100

Data Sources

NVD EPSS GitHub