imPC@ndo IT

Tracker / CVE-2005-3352

CVE-2005-3352

Medium 4.3

Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.

Affected products and versions

apache http_server
apache http_server · … → 1.3.35
apache http_server · 2.0 → 2.0.56

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References