CVE-2005-3352
EPSS 28.1%apache - missing input sanitising
發布日:2005/12/13修改日:2026/4/28
描述
Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.
受影響套件(2)
- Debian/apachefrom 0, < 1.3.33-6sarge3
- Debian/apache2from 0, < 2.0.55-4