CVE-2007-5000Cross-site Scripting in Apache Http Server

CWE-79Cross-site Scripting14 documents9 sources
Severity
4.3MEDIUMNVD
EPSS
78.1%
top 0.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 13
Latest updateMay 1

Description

Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2) mod_imagemap module in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages5 packages

NVDapache/http_server1.3.01.3.39+2
NVDoracle/http_server10.1.3.5.0
NVDopensuse/opensuse10.2, 10.3+1

Also affects: Fedora 7, 8, Ubuntu Linux 6.06, 6.10, 7.04, 7.10

🔴Vulnerability Details

3
GHSA
GHSA-wxg8-rr3m-222p: Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 12022-05-01
CVEList
CVE-2007-5000: Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 12007-12-13
OSV
CVE-2007-5000: Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 12007-12-13

💥Exploits & PoCs

6
Exploit-DB
Microsoft Office 2007 - 'OGL.dll' ValidateBitmapInfo Bounds Check Failure (MS15-097)2015-09-16
Exploit-DB
Microsoft Office 2007 - BIFFRecord Length Use-After-Free2015-09-16
Exploit-DB
Microsoft Office 2007 - OLESSDirectyEntry.CreateTime Type Confusion2015-09-16
Exploit-DB
Microsoft Office 2007 - MSPTLS Heap Index Integer Underflow (MS15-081)2015-08-21
Exploit-DB
SmartFTP Client 2.0.1002 - Remote Heap Overflow Denial of Service2007-02-06

📋Vendor Advisories

3
Ubuntu
Apache vulnerabilities2008-02-04
Red Hat
httpd: mod_imagemap XSS2007-12-11
Debian
CVE-2007-5000: apache2 - Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apach...2007

💬Community

1
Bugzilla
CVE-2007-5000 httpd: mod_imagemap XSS2007-12-11
CVE-2007-5000 — Cross-site Scripting in Apache | cvebase