cbcvebase.
CVE-2007-5000
published 2007-12-13

CVE-2007-5000: Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2)…

PriorityP428medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
46.60%
98.7th percentile
Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2) mod_imagemap module in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Affected

16 ranges
VendorProductVersion rangeFixed in
apachehttp_server1.3.0 – 1.3.39
apachehttp_server2.0.35 – 2.0.61
apachehttp_server2.2.0 – 2.2.6
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianapache2< apache2 2.2.8-1 (bookworm)apache2 2.2.8-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
opensuseopensuse
opensuseopensuse
oraclehttp_server
suselinux_enterprise_desktop
suselinux_enterprise_server
suselinux_enterprise_server

Detection & IOCsextracted from sources · hover to see the quote

  • The XSS vulnerability exists specifically when mod_imagemap (Apache 2.2.x) or mod_imap (Apache 1.3.x / 2.0.x) is enabled and an imagemap file is publicly accessible — focus detection on requests to imagemap-handled endpoints with injected script content in the URI
  • The fix escapes the URI in the menu_header function of mod_imagemap.c — detect unescaped script injection payloads (e.g., <script>, javascript:) appearing in the URI reflected in imagemap menu responses
  • Vulnerable Apache versions to flag in asset inventory: mod_imap in Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61; mod_imagemap in Apache HTTP Server 2.2.0 through 2.2.6
  • ·Vulnerability is only exploitable when mod_imagemap (2.2.x) or mod_imap (1.3.x/2.0.x) is enabled AND an imagemap file is publicly available — sites without these conditions are not exposed
  • ·Red Hat Directory Server 8 (httpd package) was marked 'Will not fix' for this CVE — deployments on that platform remain permanently vulnerable unless mitigated at another layer
  • ·The fix also adds a charset parameter to the Content-Type header to prevent MIME-type autodetection by broken browsers — absence of this header on imagemap responses can indicate an unpatched server

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.