Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2) mod_imagemap module in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS Details
- CVSS 3.1 Base Score: 6.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Apr 12, 2012 | Dec 13, 2007 |
| Apache Httpd 2_0_x Mod_imagemap Xss | — | — | Dec 6, 2010 | Dec 13, 2007 |
| Apache Httpd 2_0_x Mod_imap Xss | — | — | Aug 16, 2010 | Dec 13, 2007 |
| Apache Httpd 2_2_x Mod_imagemap Xss | — | — | Aug 16, 2010 | Dec 13, 2007 |
| Apple Osx Apache | — | Apply OS X security update 2008-003 | Dec 16, 2011 | Dec 13, 2007 |
| Debian | — | Upgrade apache2 | Jul 30, 2024 | Dec 13, 2007 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Mar 19, 2013 |
| Oracle_linux | — | Upgrade httpdUpgrade httpd-manualUpgrade httpd-develUpgrade mod_ssl | Oct 16, 2024 | Dec 13, 2007 |
| Suse | — | Upgrade apache2-develUpgrade apache2-manualUpgrade apache2-preforkUpgrade apache2-example-pagesUpgrade apache2-docUpgrade apache2Upgrade apache2-eventUpgrade apache2-workerUpgrade apache2-utils | Feb 17, 2015 | Jul 9, 2013 |
| Ubuntu | — | Upgrade apache2-mpm-perchildUpgrade apache2-mpm-workerUpgrade apache2-mpm-eventUpgrade apache2-mpm-prefork | Nov 8, 2024 | Dec 13, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub