CVE-2005-3352
UnknownEPSS 73.69%
Last modified
CVE-2005-3352 is a vulnerability of currently unknown severity. Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.. EPSS estimates a 73.69% chance of exploitation in the next 30 days.
Description
Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Http Server | < 1.3.35 |
| Apache | Http Server | >= 2.0, < 2.0.56 |
| Apache | Http Server | 2.2 |
References
- http://issues.apache.org/bugzilla/show_bug.cgi?id=37874Issue Tracking
- http://marc.info/?l=bugtraq&m=130497311408250&w=2Mailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2006-0159.htmlThird Party Advisory
- http://secunia.com/advisories/17319Not Applicable, URL Repurposed
- http://secunia.com/advisories/18008Not Applicable
- http://secunia.com/advisories/18333Not Applicable
- http://secunia.com/advisories/18339Not Applicable
- http://secunia.com/advisories/18340Not Applicable
- http://secunia.com/advisories/18429Not Applicable
- http://secunia.com/advisories/18517Not Applicable
- http://secunia.com/advisories/18526Not Applicable
- http://secunia.com/advisories/18585Not Applicable
- http://secunia.com/advisories/18743Not Applicable
- http://secunia.com/advisories/19012Not Applicable
- http://secunia.com/advisories/20046Not Applicable
- http://secunia.com/advisories/20670Not Applicable
- http://secunia.com/advisories/21744Not Applicable, Third Party Advisory
- http://secunia.com/advisories/22140Third Party Advisory
- http://secunia.com/advisories/22368Third Party Advisory
- http://secunia.com/advisories/22388Third Party Advisory
- http://secunia.com/advisories/22669Third Party Advisory
- http://secunia.com/advisories/23260Third Party Advisory
- http://secunia.com/advisories/25239Third Party Advisory
- http://secunia.com/advisories/29420Third Party Advisory
- http://secunia.com/advisories/29849Third Party Advisory
- http://secunia.com/advisories/30430Third Party Advisory
- http://securitytracker.com/id?1015344Patch, Third Party Advisory, VDB Entry
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102662-1Third Party Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102663-1Third Party Advisory
- http://www-1.ibm.com/support/search.wss?rs=0&q=PK16139&apar=onlyThird Party Advisory
- http://www-1.ibm.com/support/search.wss?rs=0&q=PK25355&apar=onlyThird Party Advisory
- http://www.debian.org/security/2006/dsa-1167Third Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200602-03.xmlThird Party Advisory
- http://www.novell.com/linux/security/advisories/2006_43_apache.htmlThird Party Advisory
- http://www.openpkg.org/security/OpenPKG-SA-2005.029-apache.txtThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.htmlThird Party Advisory
- http://www.redhat.com/archives/fedora-announce-list/2006-January/msg00060.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2006-0158.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/425399/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/445206/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/450315/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/450321/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/15834Third Party Advisory, VDB Entry
- http://www.trustix.org/errata/2005/0074/Third Party Advisory
- http://www.ubuntulinux.org/usn/usn-241-1Third Party Advisory
- http://www.us-cert.gov/cas/techalerts/TA08-150A.htmlThird Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2005/2870Third Party Advisory
- http://www.vupen.com/english/advisories/2006/2423Third Party Advisory
- http://www.vupen.com/english/advisories/2006/3995Third Party Advisory
- http://www.vupen.com/english/advisories/2006/4015Third Party Advisory
- http://www.vupen.com/english/advisories/2006/4300Third Party Advisory
- http://www.vupen.com/english/advisories/2006/4868Third Party Advisory
- http://www.vupen.com/english/advisories/2008/0924/referencesThird Party Advisory
- http://www.vupen.com/english/advisories/2008/1246/referencesThird Party Advisory
- http://www.vupen.com/english/advisories/2008/1697Third Party Advisory
- http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:007Third Party Advisory
- http://issues.apache.org/bugzilla/show_bug.cgi?id=37874Issue Tracking
- http://marc.info/?l=bugtraq&m=130497311408250&w=2Mailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2006-0159.htmlThird Party Advisory
- http://secunia.com/advisories/17319Not Applicable, URL Repurposed
- http://secunia.com/advisories/18008Not Applicable
- http://secunia.com/advisories/18333Not Applicable
- http://secunia.com/advisories/18339Not Applicable
- http://secunia.com/advisories/18340Not Applicable
- http://secunia.com/advisories/18429Not Applicable
- http://secunia.com/advisories/18517Not Applicable
- http://secunia.com/advisories/18526Not Applicable
- http://secunia.com/advisories/18585Not Applicable
- http://secunia.com/advisories/18743Not Applicable
- http://secunia.com/advisories/19012Not Applicable
- http://secunia.com/advisories/20046Not Applicable
- http://secunia.com/advisories/20670Not Applicable
- http://secunia.com/advisories/21744Not Applicable, Third Party Advisory
- http://secunia.com/advisories/22140Third Party Advisory
- http://secunia.com/advisories/22368Third Party Advisory
- http://secunia.com/advisories/22388Third Party Advisory
- http://secunia.com/advisories/22669Third Party Advisory
- http://secunia.com/advisories/23260Third Party Advisory
- http://secunia.com/advisories/25239Third Party Advisory
- http://secunia.com/advisories/29420Third Party Advisory
- http://secunia.com/advisories/29849Third Party Advisory
- http://secunia.com/advisories/30430Third Party Advisory
- http://securitytracker.com/id?1015344Patch, Third Party Advisory, VDB Entry
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102662-1Third Party Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102663-1Third Party Advisory
- http://www-1.ibm.com/support/search.wss?rs=0&q=PK16139&apar=onlyThird Party Advisory
- http://www-1.ibm.com/support/search.wss?rs=0&q=PK25355&apar=onlyThird Party Advisory
- http://www.debian.org/security/2006/dsa-1167Third Party Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200602-03.xmlThird Party Advisory
- http://www.novell.com/linux/security/advisories/2006_43_apache.htmlThird Party Advisory
- http://www.openpkg.org/security/OpenPKG-SA-2005.029-apache.txtThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.htmlThird Party Advisory
- http://www.redhat.com/archives/fedora-announce-list/2006-January/msg00060.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2006-0158.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/425399/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/445206/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/450315/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/450321/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/15834Third Party Advisory, VDB Entry
- http://www.trustix.org/errata/2005/0074/Third Party Advisory
- http://www.ubuntulinux.org/usn/usn-241-1Third Party Advisory
- http://www.us-cert.gov/cas/techalerts/TA08-150A.htmlThird Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2005/2870Third Party Advisory
- http://www.vupen.com/english/advisories/2006/2423Third Party Advisory
- http://www.vupen.com/english/advisories/2006/3995Third Party Advisory
- http://www.vupen.com/english/advisories/2006/4015Third Party Advisory
- http://www.vupen.com/english/advisories/2006/4300Third Party Advisory
- http://www.vupen.com/english/advisories/2006/4868Third Party Advisory
- http://www.vupen.com/english/advisories/2008/0924/referencesThird Party Advisory
- http://www.vupen.com/english/advisories/2008/1246/referencesThird Party Advisory
- http://www.vupen.com/english/advisories/2008/1697Third Party Advisory
- http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:007Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-3352?
Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.
How severe is CVE-2005-3352?
Severity scoring for CVE-2005-3352 is pending analysis. The EPSS model estimates a 73.69% probability of exploitation in the next 30 days.
How do I fix CVE-2005-3352?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
Are you affected by CVE-2005-3352?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
