CVE-2007-5000
published 2007-12-13CVE-2007-5000: Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2)…
PriorityP428medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
46.60%
98.7th percentile
Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2) mod_imagemap module in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | 1.3.0 – 1.3.39 | — |
| apache | http_server | 2.0.35 – 2.0.61 | — |
| apache | http_server | 2.2.0 – 2.2.6 | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | apache2 | < apache2 2.2.8-1 (bookworm) | apache2 2.2.8-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| oracle | http_server | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The XSS vulnerability exists specifically when mod_imagemap (Apache 2.2.x) or mod_imap (Apache 1.3.x / 2.0.x) is enabled and an imagemap file is publicly accessible — focus detection on requests to imagemap-handled endpoints with injected script content in the URI ↗
- →The fix escapes the URI in the menu_header function of mod_imagemap.c — detect unescaped script injection payloads (e.g., <script>, javascript:) appearing in the URI reflected in imagemap menu responses ↗
- →Vulnerable Apache versions to flag in asset inventory: mod_imap in Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61; mod_imagemap in Apache HTTP Server 2.2.0 through 2.2.6 ↗
- ·Vulnerability is only exploitable when mod_imagemap (2.2.x) or mod_imap (1.3.x/2.0.x) is enabled AND an imagemap file is publicly available — sites without these conditions are not exposed ↗
- ·Red Hat Directory Server 8 (httpd package) was marked 'Will not fix' for this CVE — deployments on that platform remain permanently vulnerable unless mitigated at another layer ↗
- ·The fix also adds a charset parameter to the Content-Type header to prevent MIME-type autodetection by broken browsers — absence of this header on imagemap responses can indicate an unpatched server ↗
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wxg8-rr3m-222p: Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1
ghsa_unreviewed·2022-05-01
CVE-2007-5000 [MEDIUM] CWE-79 GHSA-wxg8-rr3m-222p: Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1
Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2) mod_imagemap module in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
OSV
CVE-2007-5000: Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1
osv·2007-12-13·CVSS 4.3
CVE-2007-5000 [MEDIUM] CVE-2007-5000: Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1
Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2) mod_imagemap module in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Ubuntu
Apache vulnerabilities
vendor_ubuntu·2008-02-04·CVSS 4.3
CVE-2006-3918 [MEDIUM] Apache vulnerabilities
Title: Apache vulnerabilities
Summary: Apache vulnerabilities
It was discovered that Apache did not sanitize the Expect header from
an HTTP request when it is reflected back in an error message, which
could result in browsers becoming vulnerable to cross-site scripting
attacks when processing the output. With cross-site scripting
vulnerabilities, if a user were tricked into viewing server output
during a crafted server request, a remote attacker could exploit this
to modify the contents, or steal confidential data (such as passwords),
within the same domain. This was only vulnerable in Ubuntu 6.06.
(CVE-2006-3918)
It was discovered that when configured as a proxy server and using a
threaded MPM, Apache did not properly sanitize its input. A remote
attacker could send Apache crafted date
Red Hat
httpd: mod_imagemap XSS
vendor_redhat·2007-12-11·CVSS 4.3
CVE-2007-5000 [MEDIUM] CWE-79 httpd: mod_imagemap XSS
httpd: mod_imagemap XSS
Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2) mod_imagemap module in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Package: httpd (Red Hat Directory Server 8) - Will not fix
Debian
CVE-2007-5000: apache2 - Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apach...
vendor_debian·2007·CVSS 4.3
CVE-2007-5000 [MEDIUM] CVE-2007-5000: apache2 - Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apach...
Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2) mod_imagemap module in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 2.2.8-1)
bullseye: resolved (fixed in 2.2.8-1)
forky: resolved (fixed in 2.2.8-1)
sid: resolved (fixed in 2.2.8-1)
trixie: resolved (fixed in 2.2.8-1)
No detection rules found.
Exploit-DB
Microsoft Office 2007 - 'OGL.dll' ValidateBitmapInfo Bounds Check Failure (MS15-097)
exploitdb·2015-09-16
CVE-2015-2510 Microsoft Office 2007 - 'OGL.dll' ValidateBitmapInfo Bounds Check Failure (MS15-097)
Microsoft Office 2007 - 'OGL.dll' ValidateBitmapInfo Bounds Check Failure (MS15-097)
---
Source: https://code.google.com/p/google-security-research/issues/detail?id=469
The following crash was observed in Microsoft Office 2007 Excel with Microsoft Office File Validation Add-In disabled and Application Verifier enabled for testing and reproduction. This bug did not reproduce in Office 2010 or 2013.
Attached files:
Original File: 3013413838_orig.xls
Crashing File: 3013413838_crash.xls
Minimized Crashing File: 3013413838_min.xls
The minimized crashing file shows a one bit delta from the original file at offset 0x139F. OffVis did not reveal anything unique about this offset in the minimized file.
File Versions:
Excel.exe: 12.0.6718.5000
OGL.dll: 12.0.6719.5000
oart.dll: 12.0.6683.5002
GD
Exploit-DB
Microsoft Office 2007 - BIFFRecord Length Use-After-Free
exploitdb·2015-09-16
CVE-2015-2520 Microsoft Office 2007 - BIFFRecord Length Use-After-Free
Microsoft Office 2007 - BIFFRecord Length Use-After-Free
---
Source: https://code.google.com/p/google-security-research/issues/detail?id=464
The following crash was observed in Microsoft Office 2007 with Microsoft Office File Validation Add-In disabled and Application Verifier enabled for testing and reproduction. This bug did not reproduce in Office 2010 or 2013.
Attached files:
Original File: 1105668828_orig.xls
Crashing File: 1105668828_crash.xls
Minimized Crashing File: 1105668828_min.xls
The minimized crashing file shows two one bit deltas from the original file. The first delta at offset 0x1CF7E and the second is at offset 0x3A966. Both of these offset appear to be BIFFRecord lengths.
File Versions:
Excel.exe: 12.0.6718.5000
MSO.dll: 12.0.6721.5000
Observed Crash:
eax=0000000
Exploit-DB
Microsoft Office 2007 - OLESSDirectyEntry.CreateTime Type Confusion
exploitdb·2015-09-16
CVE-2015-2521 Microsoft Office 2007 - OLESSDirectyEntry.CreateTime Type Confusion
Microsoft Office 2007 - OLESSDirectyEntry.CreateTime Type Confusion
---
Source: https://code.google.com/p/google-security-research/issues/detail?id=465
The following crash was observed in Microsoft Office 2007 with Microsoft Office File Validation Add-In disabled and Application Verifier enabled for testing and reproduction. This bug did not reproduce in Office 2010 or 2013.
Attached files:
Original File: 1516065514_orig.xls
Crashing File: 1516065514_crash.xls
Minimized Crashing File: 1516065514_min.xls
The minimized crashing file shows a one bit deltas from the original file at offset 0x49E8. OffVis reports this to be the CreateTime field of an OLESSDirectoryEntry structure.
File Versions:
Excel.exe: 12.0.6718.5000
MSO.dll: 12.0.6721.5000
Observed Crash:
When run without Applicati
Exploit-DB
Microsoft Office 2007 - MSPTLS Heap Index Integer Underflow (MS15-081)
exploitdb·2015-08-21
CVE-2015-2470 Microsoft Office 2007 - MSPTLS Heap Index Integer Underflow (MS15-081)
Microsoft Office 2007 - MSPTLS Heap Index Integer Underflow (MS15-081)
---
Source: https://code.google.com/p/google-security-research/issues/detail?id=431&can=1
The following crash was observed in Microsoft Office 2007 with Microsoft Office File Validation Add-In disabled and Application Verifier enabled for testing and reproduction. This bug also reproduced in Office 2010 running on Windows 7 x86.
The crash is caused by a 1 bit delta from the original file at offset 0xA9B0. Standard tools did not identify anything significant about this offset in the minimized file.
Attached files:
Fuzzed minimized PoC: 3423415565_min.doc
Fuzzed non-minimized PoC: 3423415565_crash.doc
Original non-fuzzed file: 3423415565_orig.doc
DLL Versions:
wwlib.dll: 12.0.6720.5000
msptls.dll: 12.0.6682.5000
Exploit-DB
SmartFTP Client 2.0.1002 - Remote Heap Overflow Denial of Service
exploitdb·2007-02-06
CVE-2007-0790 SmartFTP Client 2.0.1002 - Remote Heap Overflow Denial of Service
SmartFTP Client 2.0.1002 - Remote Heap Overflow Denial of Service
---
/***************************************************************************
* SmartFTP Client v 2.0.1002 Heap Overflow DoS *
* *
* *
* There is remote heap overflow in SmartFTP. When the app receives a long *
* banner (5000 char) the heap is smashed, leading to DoS and to code *
* execution. *
* *
* There are also two buffer overflow in the fields Address and Login. *
* I've reported this to Secunia but it seems they didn't think it was dan- *
* gerous cause they didn't publish anything about. However a simple drag'n *
* drop could compromise your system... *
* *
* Have Fun! *
* *
* Coded by Marsu *
***************************************************************************/
#include "winsock2.h"
#include "stdio.h"
Exploit-DB
BolinTech DreamFTP Server - 'USER' Remote Buffer Overflow (PoC)
exploitdb·2007-01-14
CVE-2007-0338 BolinTech DreamFTP Server - 'USER' Remote Buffer Overflow (PoC)
BolinTech DreamFTP Server - 'USER' Remote Buffer Overflow (PoC)
---
/**************************************************************************
*BolinTech DreamFTP USER buffer overflow *
* *
*The server does not correctly handle format string so sending a command *
*like USER %1*3000 let us own EDX. Other values can also affect EAX & ECX *
* *
*This is only a POC but code execution is possible *
* *
*usage: dreamftp.exe ip port *
* *
*Coded by Marsu *
**************************************************************************/
#include "winsock2.h"
#include "stdio.h"
#include "stdlib.h"
#pragma comment(lib, "ws2_32.lib")
int main(int argc, char* argv[])
{
struct hostent *he;
struct sockaddr_in sock_addr;
WSADATA wsa;
int ftpsock;
char recvbuff[1024];
char evilbuff[5003];
int buflen=5000
http://docs.info.apple.com/article.html?artnum=307562http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01345501http://httpd.apache.org/security/vulnerabilities_13.htmlhttp://httpd.apache.org/security/vulnerabilities_20.htmlhttp://httpd.apache.org/security/vulnerabilities_22.htmlhttp://lists.apple.com/archives/security-announce/2008//May/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2008/Mar/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-04/msg00004.htmlhttp://lists.vmware.com/pipermail/security-announce/2009/000062.htmlhttp://marc.info/?l=bugtraq&m=130497311408250&w=2http://secunia.com/advisories/28046http://secunia.com/advisories/28073http://secunia.com/advisories/28081http://secunia.com/advisories/28196http://secunia.com/advisories/28375http://secunia.com/advisories/28467http://secunia.com/advisories/28471http://secunia.com/advisories/28525http://secunia.com/advisories/28526http://secunia.com/advisories/28607http://secunia.com/advisories/28749http://secunia.com/advisories/28750http://secunia.com/advisories/28922http://secunia.com/advisories/28977http://secunia.com/advisories/29420http://secunia.com/advisories/29640http://secunia.com/advisories/29806http://secunia.com/advisories/29988http://secunia.com/advisories/30356http://secunia.com/advisories/30430http://secunia.com/advisories/30732http://secunia.com/advisories/31142http://secunia.com/advisories/32800http://securitytracker.com/id?1019093http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.595748http://sunsolve.sun.com/search/document.do?assetkey=1-26-233623-1http://support.avaya.com/elmodocs2/security/ASA-2008-032.htmhttp://www-1.ibm.com/support/docview.wss?uid=swg1PK58024http://www-1.ibm.com/support/docview.wss?uid=swg1PK58074http://www-1.ibm.com/support/docview.wss?uid=swg1PK63273http://www-1.ibm.com/support/docview.wss?uid=swg24019245http://www.fujitsu.com/global/support/software/security/products-f/interstage-200801e.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:014http://www.mandriva.com/security/advisories?name=MDVSA-2008:015http://www.mandriva.com/security/advisories?name=MDVSA-2008:016http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.htmlhttp://www.osvdb.org/39134http://www.redhat.com/support/errata/RHSA-2008-0004.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0005.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0006.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0007.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0008.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0009.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0261.htmlhttp://www.securityfocus.com/archive/1/494428/100/0/threadedhttp://www.securityfocus.com/archive/1/498523/100/0/threadedhttp://www.securityfocus.com/archive/1/505990/100/0/threadedhttp://www.securityfocus.com/bid/26838http://www.ubuntu.com/usn/usn-575-1http://www.us-cert.gov/cas/techalerts/TA08-150A.htmlhttp://www.vupen.com/english/advisories/2007/4201http://www.vupen.com/english/advisories/2007/4202http://www.vupen.com/english/advisories/2007/4301http://www.vupen.com/english/advisories/2008/0084http://www.vupen.com/english/advisories/2008/0178http://www.vupen.com/english/advisories/2008/0398http://www.vupen.com/english/advisories/2008/0809/referenceshttp://www.vupen.com/english/advisories/2008/0924/referenceshttp://www.vupen.com/english/advisories/2008/1224/referenceshttp://www.vupen.com/english/advisories/2008/1623/referenceshttp://www.vupen.com/english/advisories/2008/1697http://www.vupen.com/english/advisories/2008/1875/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/39001https://exchange.xforce.ibmcloud.com/vulnerabilities/39002https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rafd145ba6cd0a4ced113a5823cdaff45aeb36eb09855b216401c66d6%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3Ehttps://lists.apache.org/thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9539https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00541.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-February/msg00562.htmlhttp://docs.info.apple.com/article.html?artnum=307562http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01345501http://httpd.apache.org/security/vulnerabilities_13.htmlhttp://httpd.apache.org/security/vulnerabilities_20.html
+ 92 more references
2007-12-13
Published