cbcvebase.
CVE-2005-3352
published 2005-12-13

CVE-2005-3352: Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote…

PriorityP432medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
73.69%
99.4th percentile
Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.

Affected

4 ranges
VendorProductVersion rangeFixed in
apachehttp_server< 1.3.351.3.35
apachehttp_server
apachehttp_server>= 2.0 < 2.0.562.0.56
debianapache2< apache2 2.0.55-4 (bookworm)apache2 2.0.55-4 (bookworm)

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability is triggered via a crafted Referer header sent to a server using mod_imap with a map file containing the 'referer' directive — monitor for unescaped/malicious script content in Referer headers on requests to image map resources.
  • Exploitation requires the victim to visit an attacker-controlled URL; the attack is limited to certain browsers — notably Internet Explorer was confirmed exploitable while Firefox/Mozilla escape suspect URL characters and block exploitation.
  • Confirmed exploitation method: attacker constructs a victim site with vulnerable mod_imap configuration and scripts on attacker site; when IE user visits attacker site, private cookies from victim site are stolen via the injected Referer.
  • This flaw only affects Apache instances where mod_imap is enabled AND a map file contains the 'referer' directive — scope detection/alerting to those configurations.
  • ·Exploitation requires mod_imap to be active with a map file containing the 'referer' directive; sites without this configuration are not vulnerable.
  • ·A temporary mitigation (where patching is not possible) is to remove the 'referer' directive from all map files.
  • ·The attacker must be able to control the Referer header, which requires enticing a victim to visit a URL under the attacker's control.

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.