CVE-2005-3352
published 2005-12-13CVE-2005-3352: Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote…
PriorityP432medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
73.69%
99.4th percentile
Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | < 1.3.35 | 1.3.35 |
| apache | http_server | — | — |
| apache | http_server | >= 2.0 < 2.0.56 | 2.0.56 |
| debian | apache2 | < apache2 2.0.55-4 (bookworm) | apache2 2.0.55-4 (bookworm) |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability is triggered via a crafted Referer header sent to a server using mod_imap with a map file containing the 'referer' directive — monitor for unescaped/malicious script content in Referer headers on requests to image map resources. ↗
- →Exploitation requires the victim to visit an attacker-controlled URL; the attack is limited to certain browsers — notably Internet Explorer was confirmed exploitable while Firefox/Mozilla escape suspect URL characters and block exploitation. ↗
- →Confirmed exploitation method: attacker constructs a victim site with vulnerable mod_imap configuration and scripts on attacker site; when IE user visits attacker site, private cookies from victim site are stolen via the injected Referer. ↗
- →This flaw only affects Apache instances where mod_imap is enabled AND a map file contains the 'referer' directive — scope detection/alerting to those configurations. ↗
- ·Exploitation requires mod_imap to be active with a map file containing the 'referer' directive; sites without this configuration are not vulnerable. ↗
- ·A temporary mitigation (where patching is not possible) is to remove the 'referer' directive from all map files. ↗
- ·The attacker must be able to control the Referer header, which requires enticing a victim to visit a URL under the attacker's control. ↗
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3h5q-3j8q-4rm9: Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1
ghsa_unreviewed·2022-05-03
CVE-2005-3352 [MEDIUM] GHSA-3h5q-3j8q-4rm9: Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1
Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.
OSV
CVE-2005-3352: Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1
osv·2005-12-13·CVSS 4.3
CVE-2005-3352 [MEDIUM] CVE-2005-3352: Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1
Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.
Ubuntu
Apache vulnerabilities
vendor_ubuntu·2006-01-13·CVSS 4.3
CVE-2005-3352 [MEDIUM] Apache vulnerabilities
Title: Apache vulnerabilities
Summary: Apache vulnerabilities
The "mod_imap" module (which provides support for image maps) did not
properly escape the "referer" URL which rendered it vulnerable against
a cross-site scripting attack. A malicious web page (or HTML email)
could trick a user into visiting a site running the vulnerable mod_imap,
and employ cross-site-scripting techniques to gather sensitive user
information from that site. (CVE-2005-3352)
Hartmut Keil discovered a Denial of Service vulnerability in the SSL
module ("mod_ssl") that affects SSL-enabled virtual hosts with a
customized error page for error 400. By sending a specially crafted
request to the server, a remote attacker could crash the server. This
only affects Apache 2, and only if the "worker" implementation
(apach
Red Hat
httpd cross-site scripting flaw in mod_imap
vendor_redhat·2005-12-12·CVSS 4.3
CVE-2005-3352 [MEDIUM] CWE-79 httpd cross-site scripting flaw in mod_imap
httpd cross-site scripting flaw in mod_imap
Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.
Debian
CVE-2005-3352: apache2 - Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd ...
vendor_debian·2005·CVSS 4.3
CVE-2005-3352 [MEDIUM] CVE-2005-3352: apache2 - Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd ...
Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.
Scope: local
bookworm: resolved (fixed in 2.0.55-4)
bullseye: resolved (fixed in 2.0.55-4)
forky: resolved (fixed in 2.0.55-4)
sid: resolved (fixed in 2.0.55-4)
trixie: resolved (fixed in 2.0.55-4)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2005-3352 httpd cross-site scripting flaw in mod_imap
bugzilla·2008-01-28·CVSS 4.3
CVE-2005-3352 [MEDIUM] CVE-2005-3352 httpd cross-site scripting flaw in mod_imap
CVE-2005-3352 httpd cross-site scripting flaw in mod_imap
Common Vulnerabilities and Exposures assigned an identifier CVE-2005-3352 to the following vulnerability:
Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.
References:
http://issues.apache.org/bugzilla/show_bug.cgi?id=37874
http://www-1.ibm.com/support/search.wss?rs=0&q=PK16139&apar=only
http://www-1.ibm.com/support/search.wss?rs=0&q=PK25355&apar=only
http://www.debian.org/security/2006/dsa-1167
http://www.redhat.com/archives/fedora-announce-list/2006-January/msg00060.html
http://www.securityfocus.com/archive/1/archive/1/425399/100/0/threade
Bugzilla
CVE-2005-3352, CVE-2006-3918 apache security issues
bugzilla·2006-09-25·CVSS 4.3
CVE-2005-3352 [MEDIUM] CVE-2005-3352, CVE-2006-3918 apache security issues
CVE-2005-3352, CVE-2006-3918 apache security issues
Description of problem:
The following issues affect the stronghold-apache package:
CVE-2006-3918 Expect header XSS
CVE-2005-3352 cross-site scripting flaw in mod_imap
Version-Release number of selected component (if applicable):
stronghold-apache-1.3.22-25
Discussion:
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.
http://rhn.redhat.com/errata/RHSA-2006-0692.html
---
*** Bug 204049 has been marked as a duplicate of this bug. ***
Bugzilla
CVE-2005-3352 mod_imagemap XSS in FC5test2
bugzilla·2006-01-16·CVSS 4.3
CVE-2005-3352 [MEDIUM] CVE-2005-3352 mod_imagemap XSS in FC5test2
CVE-2005-3352 mod_imagemap XSS in FC5test2
From http://issues.apache.org/bugzilla/show_bug.cgi?id=37874
Summary:
A flaw in the imagemap processing module, mod_imap, in versions of Apache httpd
1.3, 2.0 and 2.2 can in some circumstances cause the referer header to be output
without being escaped in HTML. This could allow an attacker who is able to
influence the referer header the ability to do cross-site scripting attacks
against sites using mod_imap in a vulnerable configuration.
Impact:
moderate (http://httpd.apache.org/security/impact_levels.html)
Mitigation:
This flaw only affects sites using mod_imap with a map file that contains the
"referer" directive.
In order to exploit this flaw the attacker would need to control the referer
header and therefore would need to entice a vict
Bugzilla
CVE-2005-3352 cross-site scripting flaw in mod_imap
bugzilla·2005-12-14·CVSS 4.3
CVE-2005-3352 [MEDIUM] CVE-2005-3352 cross-site scripting flaw in mod_imap
CVE-2005-3352 cross-site scripting flaw in mod_imap
+++ This bug was initially created as a clone of Bug #175602 +++
From http://issues.apache.org/bugzilla/show_bug.cgi?id=37874
Summary:
A flaw in the imagemap processing module, mod_imap, in versions of Apache httpd
1.3, 2.0 and 2.2 can in some circumstances cause the referer header to be output
without being escaped in HTML. This could allow an attacker who is able to
influence the referer header the ability to do cross-site scripting attacks
against sites using mod_imap in a vulnerable configuration.
Impact:
moderate (http://httpd.apache.org/security/impact_levels.html)
Mitigation:
This flaw only affects sites using mod_imap with a map file that contains the
"referer" directive.
In order to exploit this flaw the attacker would n
Bugzilla
CVE-2005-3352 cross-site scripting flaw in mod_imap
bugzilla·2005-12-13·CVSS 4.3
CVE-2005-3352 [MEDIUM] CVE-2005-3352 cross-site scripting flaw in mod_imap
CVE-2005-3352 cross-site scripting flaw in mod_imap
From http://issues.apache.org/bugzilla/show_bug.cgi?id=37874
Summary:
A flaw in the imagemap processing module, mod_imap, in versions of Apache httpd
1.3, 2.0 and 2.2 can in some circumstances cause the referer header to be output
without being escaped in HTML. This could allow an attacker who is able to
influence the referer header the ability to do cross-site scripting attacks
against sites using mod_imap in a vulnerable configuration.
Impact:
moderate (http://httpd.apache.org/security/impact_levels.html)
Mitigation:
This flaw only affects sites using mod_imap with a map file that contains the
"referer" directive.
In order to exploit this flaw the attacker would need to control the referer
header and therefore would need to enti
Bugzilla
CVE-2005-2970, CVE-2005-3352, CVE-2005-3357 Apache httpd multiple security issues
bugzilla·2005-12-09·CVSS 7.5
CVE-2005-2970 [HIGH] CVE-2005-2970, CVE-2005-3352, CVE-2005-3357 Apache httpd multiple security issues
CVE-2005-2970, CVE-2005-3352, CVE-2005-3357 Apache httpd multiple security issues
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.5) Gecko/20051012 Netscape/8.0.4
Description of problem:
05.49.32 CVE: CVE-2005-2970
Platform: Cross Platform
Title: Apache MPM Worker.C Denial of Service
Description: Apache web-server is prone to a memory leak due to a flaw
in the "worker.c" file, causing a denial of service vulnerability.
Apache versions earlier than 2.0.55 are vulnerable.
Ref: http://www.apache.org/dist/httpd/Announcement2.0.html
Version-Release number of selected component (if applicable):
How reproducible:
Didn't try
Additional info:
Discussion:
New issue: CVE-2005-3352 cross-site scripting flaw in mod_imap
Ref: Fedora Core: Bug #175714
Ref
ftp://patches.sgi.com/support/free/security/advisories/20060101-01-Uhttp://docs.info.apple.com/article.html?artnum=307562http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01428449http://issues.apache.org/bugzilla/show_bug.cgi?id=37874http://lists.apple.com/archives/security-announce/2008//May/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2008/Mar/msg00001.htmlhttp://lists.suse.com/archive/suse-security-announce/2007-May/0005.htmlhttp://lists.suse.de/archive/suse-security-announce/2006-Feb/0008.htmlhttp://marc.info/?l=bugtraq&m=130497311408250&w=2http://rhn.redhat.com/errata/RHSA-2006-0159.htmlhttp://rhn.redhat.com/errata/RHSA-2006-0692.htmlhttp://secunia.com/advisories/17319http://secunia.com/advisories/18008http://secunia.com/advisories/18333http://secunia.com/advisories/18339http://secunia.com/advisories/18340http://secunia.com/advisories/18429http://secunia.com/advisories/18517http://secunia.com/advisories/18526http://secunia.com/advisories/18585http://secunia.com/advisories/18743http://secunia.com/advisories/19012http://secunia.com/advisories/20046http://secunia.com/advisories/20670http://secunia.com/advisories/21744http://secunia.com/advisories/22140http://secunia.com/advisories/22368http://secunia.com/advisories/22388http://secunia.com/advisories/22669http://secunia.com/advisories/23260http://secunia.com/advisories/25239http://secunia.com/advisories/29420http://secunia.com/advisories/29849http://secunia.com/advisories/30430http://securitytracker.com/id?1015344http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.470158http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.685483http://sunsolve.sun.com/search/document.do?assetkey=1-26-102662-1http://sunsolve.sun.com/search/document.do?assetkey=1-26-102663-1http://www-1.ibm.com/support/search.wss?rs=0&q=PK16139&apar=onlyhttp://www-1.ibm.com/support/search.wss?rs=0&q=PK25355&apar=onlyhttp://www.debian.org/security/2006/dsa-1167http://www.gentoo.org/security/en/glsa/glsa-200602-03.xmlhttp://www.novell.com/linux/security/advisories/2006_43_apache.htmlhttp://www.openpkg.org/security/OpenPKG-SA-2005.029-apache.txthttp://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.htmlhttp://www.redhat.com/archives/fedora-announce-list/2006-January/msg00060.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0158.htmlhttp://www.securityfocus.com/archive/1/425399/100/0/threadedhttp://www.securityfocus.com/archive/1/445206/100/0/threadedhttp://www.securityfocus.com/archive/1/450315/100/0/threadedhttp://www.securityfocus.com/archive/1/450321/100/0/threadedhttp://www.securityfocus.com/bid/15834http://www.trustix.org/errata/2005/0074/http://www.ubuntulinux.org/usn/usn-241-1http://www.us-cert.gov/cas/techalerts/TA08-150A.htmlhttp://www.vupen.com/english/advisories/2005/2870http://www.vupen.com/english/advisories/2006/2423http://www.vupen.com/english/advisories/2006/3995http://www.vupen.com/english/advisories/2006/4015http://www.vupen.com/english/advisories/2006/4300http://www.vupen.com/english/advisories/2006/4868http://www.vupen.com/english/advisories/2008/0924/referenceshttp://www.vupen.com/english/advisories/2008/1246/referenceshttp://www.vupen.com/english/advisories/2008/1697http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:007https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r652fc951306cdeca5a276e2021a34878a76695a9f3cfb6490b4a6840%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rafd145ba6cd0a4ced113a5823cdaff45aeb36eb09855b216401c66d6%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/reb542d2038e9c331506e0cbff881b47e40fbe2bd93ff00979e60cdf7%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10480ftp://patches.sgi.com/support/free/security/advisories/20060101-01-Uhttp://docs.info.apple.com/article.html?artnum=307562http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01428449http://issues.apache.org/bugzilla/show_bug.cgi?id=37874http://lists.apple.com/archives/security-announce/2008//May/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2008/Mar/msg00001.htmlhttp://lists.suse.com/archive/suse-security-announce/2007-May/0005.htmlhttp://lists.suse.de/archive/suse-security-announce/2006-Feb/0008.htmlhttp://marc.info/?l=bugtraq&m=130497311408250&w=2http://rhn.redhat.com/errata/RHSA-2006-0159.htmlhttp://rhn.redhat.com/errata/RHSA-2006-0692.htmlhttp://secunia.com/advisories/17319http://secunia.com/advisories/18008http://secunia.com/advisories/18333http://secunia.com/advisories/18339http://secunia.com/advisories/18340http://secunia.com/advisories/18429http://secunia.com/advisories/18517http://secunia.com/advisories/18526
+ 62 more references
2005-12-13
Published