Back
CVE-2005-3352
Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.
Published: Dec 13, 2005
Modified: Jun 16, 2026
CWE-79
CVSS Metrics
Affected Products (3)
| Vendor | Product | Version |
|---|---|---|
| apache | http_server | * < 1.3.35 |
| apache | http_server | * ≥ 2.0 < 2.0.56 |
| apache | http_server | 2.2 |
GitHub Security Advisory GHSA-3h5q-3j8q-4rm9
Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev...
References (162)
- ftp://patches.sgi.com/support/free/security/advisories/20060101-01-U Broken Link
- http://docs.info.apple.com/article.html?artnum=307562 Broken Link
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01428449 Broken Link
- http://issues.apache.org/bugzilla/show_bug.cgi?id=37874 Issue Tracking
- http://lists.apple.com/archives/security-announce/2008//May/msg00001.html Mailing List
- http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html Mailing List
- http://lists.suse.com/archive/suse-security-announce/2007-May/0005.html Broken Link
- http://lists.suse.de/archive/suse-security-announce/2006-Feb/0008.html Broken Link
- http://marc.info/?l=bugtraq&m=130497311408250&w=2 Mailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2006-0159.html Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2006-0692.html Broken Link
- http://secunia.com/advisories/17319 Not Applicable, URL Repurposed
- http://secunia.com/advisories/18008 Not Applicable
- http://secunia.com/advisories/18333 Not Applicable
- http://secunia.com/advisories/18339 Not Applicable
Risk Scores
CVSS Score
4.3 / 10
EPSS Score
73.69%
Top 1% most likely to be exploited
Threat Score
49.3 / 100
Data Sources
NVD
EPSS
GitHub