CVE-2005-3352

Description

Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.

Risk Information

Base Score
6.1
MODERATE
Vector
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
37.141

Associated Vulnerability

VulnerabilityOS Platform
Update Apache to version 2.0.58Windows
Update Apache to version 1.3.33Windows
Vulnerabilities CVE-2005-3352 are fixed in Apache 2.2.2Windows
Vulnerabilities CVE-2005-3352 are fixed in Apache 1.3.35Windows
Vulnerabilities CVE-2005-3352 are fixed in Apache 2.0.58Windows
Multiple vulnerabilities are affected in Oracle HTTP Server 4.3Windows
Update Apache to version 2.0.58 (For Linux)Linux
Update Apache to version 1.3.33 (For Linux)Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234