Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.

Project Subscriptions

Vendors Products
Http Server Subscribe
Enterprise Linux Subscribe
Network Proxy Subscribe
Rhel Stronghold Subscribe
Stronghold Subscribe
Advisories
Source ID Title
Debian DSA Debian DSA DSA-1167-1 New apache packages fix several vulnerabilities
Ubuntu USN Ubuntu USN USN-241-1 Apache vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
ftp://patches.sgi.com/support/free/security/advisories/20060101-01-U cve-icon cve-icon
http://docs.info.apple.com/article.html?artnum=307562 cve-icon cve-icon
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01428449 cve-icon cve-icon
http://issues.apache.org/bugzilla/show_bug.cgi?id=37874 cve-icon cve-icon
http://lists.apple.com/archives/security-announce/2008//May/msg00001.html cve-icon cve-icon
http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html cve-icon cve-icon
http://lists.suse.com/archive/suse-security-announce/2007-May/0005.html cve-icon cve-icon
http://lists.suse.de/archive/suse-security-announce/2006-Feb/0008.html cve-icon cve-icon
http://marc.info/?l=bugtraq&m=130497311408250&w=2 cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2006-0159.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2006-0692.html cve-icon cve-icon
http://secunia.com/advisories/17319 cve-icon cve-icon
http://secunia.com/advisories/18008 cve-icon cve-icon
http://secunia.com/advisories/18333 cve-icon cve-icon
http://secunia.com/advisories/18339 cve-icon cve-icon
http://secunia.com/advisories/18340 cve-icon cve-icon
http://secunia.com/advisories/18429 cve-icon cve-icon
http://secunia.com/advisories/18517 cve-icon cve-icon
http://secunia.com/advisories/18526 cve-icon cve-icon
http://secunia.com/advisories/18585 cve-icon cve-icon
http://secunia.com/advisories/18743 cve-icon cve-icon
http://secunia.com/advisories/19012 cve-icon cve-icon
http://secunia.com/advisories/20046 cve-icon cve-icon
http://secunia.com/advisories/20670 cve-icon cve-icon
http://secunia.com/advisories/21744 cve-icon cve-icon
http://secunia.com/advisories/22140 cve-icon cve-icon
http://secunia.com/advisories/22368 cve-icon cve-icon
http://secunia.com/advisories/22388 cve-icon cve-icon
http://secunia.com/advisories/22669 cve-icon cve-icon
http://secunia.com/advisories/23260 cve-icon cve-icon
http://secunia.com/advisories/25239 cve-icon cve-icon
http://secunia.com/advisories/29420 cve-icon cve-icon
http://secunia.com/advisories/29849 cve-icon cve-icon
http://secunia.com/advisories/30430 cve-icon cve-icon
http://securitytracker.com/id?1015344 cve-icon cve-icon
http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.470158 cve-icon cve-icon
http://slackware.com/security/viewer.php?l=slackware-security&y=2006&m=slackware-security.685483 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102662-1 cve-icon cve-icon
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102663-1 cve-icon cve-icon
http://www-1.ibm.com/support/search.wss?rs=0&q=PK16139&apar=only cve-icon cve-icon
http://www-1.ibm.com/support/search.wss?rs=0&q=PK25355&apar=only cve-icon cve-icon
http://www.debian.org/security/2006/dsa-1167 cve-icon cve-icon
http://www.gentoo.org/security/en/glsa/glsa-200602-03.xml cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2006_43_apache.html cve-icon cve-icon
http://www.openpkg.org/security/OpenPKG-SA-2005.029-apache.txt cve-icon cve-icon
http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html cve-icon cve-icon
http://www.redhat.com/archives/fedora-announce-list/2006-January/msg00060.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2006-0158.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/425399/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/445206/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/450315/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/450321/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/15834 cve-icon cve-icon
http://www.trustix.org/errata/2005/0074/ cve-icon cve-icon
http://www.ubuntulinux.org/usn/usn-241-1 cve-icon cve-icon
http://www.us-cert.gov/cas/techalerts/TA08-150A.html cve-icon cve-icon
http://www.vupen.com/english/advisories/2005/2870 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/2423 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/3995 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/4015 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/4300 cve-icon cve-icon
http://www.vupen.com/english/advisories/2006/4868 cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/0924/references cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/1246/references cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/1697 cve-icon cve-icon
http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:007 cve-icon cve-icon
https://lists.apache.org/thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r652fc951306cdeca5a276e2021a34878a76695a9f3cfb6490b4a6840%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/rafd145ba6cd0a4ced113a5823cdaff45aeb36eb09855b216401c66d6%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/reb542d2038e9c331506e0cbff881b47e40fbe2bd93ff00979e60cdf7%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2005-3352 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10480 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2005-3352 cve-icon
History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-07T23:10:08.408Z

Reserved: 2005-10-27T04:00:00.000Z

Link: CVE-2005-3352

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2005-12-13T20:03:00.000

Modified: 2025-04-03T01:03:51.193

Link: CVE-2005-3352

cve-icon Redhat

Severity : Moderate

Publid Date: 2005-12-12T00:00:00Z

Links: CVE-2005-3352 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses