Upstream information
Description
Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.SUSE information
Overall state of this security issue: Resolved
This issue is currently rated as having moderate severity.
National Vulnerability Database | |
---|---|
Base Score | 4.3 |
Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Access Vector | Network |
Access Complexity | Medium |
Authentication | None |
Confidentiality Impact | None |
Integrity Impact | Partial |
Availability Impact | None |
SUSE Security Advisories:
- SUSE-SA:2006:043, published Fri, 28 Jul 2006 17:00:00 +0000
- SUSE-SR:2006:004, published Fri, 24 Feb 2006 16:00:00 +0000
- SUSE-SR:2007:011, published Wed, 16 May 2007 15:00:00 +0000
List of released packages
Product(s) | Fixed package version(s) | References |
---|---|---|
openSUSE Tumbleweed |
| Patchnames: openSUSE Tumbleweed GA apache2-2.4.49-1.1 |
SUSE Timeline for this CVE
CVE page created: Fri Jun 28 02:09:28 2013CVE page last modified: Fri Oct 7 12:45:31 2022