Apache mod_imap Image Map Referer XSS

medium Nessus Plugin ID 31647

Synopsis

The remote web server contains a module vulnerable to a cross-site scripting attack.

Description

The remote Apache web server has the module 'mod_imap' (or 'mod_imagemap') installed. The remote version of this module is vulnerable to a cross-site scripting issue related to the handling of the 'referrer' field of the remote server.

Solution

Upgrade to Apache 1.3.35, 2.0.56 or 2.2.6.

Plugin Details

Severity: Medium

ID: 31647

File Name: mod_imap_xss.nasl

Version: 1.19

Type: remote

Family: Web Servers

Published: 3/25/2008

Updated: 7/14/2018

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.0

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.2

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Information

Required KB Items: www/apache

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 12/13/2005

Reference Information

CVE: CVE-2005-3352

BID: 15834

CWE: 20, 442, 629, 711, 712, 722, 725, 74, 750, 751, 79, 800, 801, 809, 811, 864, 900, 928, 931, 990