Vulnerability record · CVE-2005-3352 · published 13 December 2005
CVE-2005-3352: Apache httpd mod_imap XSS via Referer header
Apache · Http Server
The mod_imap module in Apache httpd before 1.3.35-dev and 2.0.x before 2.0.56-dev fails to sanitize the Referer header when serving image maps, allowing reflected cross-site scripting. An attacker can craft a request whose Referer contains script or HTML that is echoed back into the response, executing in the victim's browser in the context of the affected site.
Description
Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.
AV:N/AC:M/Au:N/C:N/I:P/A:N
Automated analysis
medium priorityThe flaw is a reflected XSS with only partial integrity impact and medium attack complexity, and no known active exploitation, though the high EPSS score and broad Apache deployment warrant attention.
What it is
The mod_imap module in Apache httpd before 1.3.35-dev and 2.0.x before 2.0.56-dev fails to sanitize the Referer header when serving image maps, allowing reflected cross-site scripting. An attacker can craft a request whose Referer contains script or HTML that is echoed back into the response, executing in the victim's browser in the context of the affected site.
Impact
An attacker can execute arbitrary script in a victim's browser session against the vulnerable server, enabling session theft, credential phishing, or page defacement within that origin. The CVSS 2.0 vector shows partial integrity impact only, with no confidentiality or availability impact.
Attack surface
Reachable remotely over the network via HTTP requests to image map resources; no authentication is required, but the CVSS vector rates attack complexity as medium, implying some conditions or user interaction are needed to deliver the malicious Referer.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented; EPSS is high at roughly 0.737 (99.4th percentile), but the reference tags show only issue tracking, mailing list, and third-party advisory links, with no public exploit reference.
What to do
- Upgrade Apache httpd to 1.3.35 or later, or 2.0.56 or later, which contain the fix for mod_imap
- If image maps are not needed, disable or remove the mod_imap module
- Apply vendor backport patches from distributions such as Red Hat, SUSE, or Apple that shipped fixes for this issue
- Add output encoding or filtering for the Referer header on any remaining image map handling
Detection
- Inspect web server access logs for requests to image map resources with unusual or script-bearing Referer values
- Search HTTP request logs for Referer headers containing angle brackets, script tags, or javascript: URIs
- Review mod_imap usage and confirm whether the module is loaded on internet-facing servers
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-3352 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-3352), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.