Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2007-5000

35
FAUCET Score

CVE-2007-5000 describes a cross-site scripting (XSS) vulnerability affecting the mod_imap and mod_imagemap modules in various versions of the Apache HTTP Server, impacting distributions like Canonical, Fedora, and OpenSUSE. This vulnerability carries a CVSS score of 4.3, indicating a medium attack complexity and potential for unauthorized information disclosure (I:P) without authentication, though it does not directly impact confidentiality or availability. Despite its high FAUCET Risk Score of 98/100 and elevated EPSS, there is no evidence of active exploitation, no known exploit code in Metasploit or ExploitDB, and minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.3.0, <= 1.3.39CPE matchmatch criteria
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*
>= 2.0.35, <= 2.0.61CPE matchmatch criteria
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*
>= 2.2.0, <= 2.2.6CPE matchmatch criteria
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*
7CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:7:*:*:*:*:*:*:*
8CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:8:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

4.3MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N

Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
46.60%
Probability of exploitation in next 30 days
EPSS Percentile
98.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.4660 is in the 99th percentile among its peer group of 19,955 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (65)

redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: ant-0:1.6.5-1jpp_1rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: avalon-logkit-0:1.2-2jpp_4rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: axis-0:1.2.1-1jpp_3rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: classpathx-jaf-0:1.0-2jpp_6rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: classpathx-mail-0:1.1.1-2jpp_8rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: geronimo-specs-0:1.0-0.M4.1jpp_10rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: jakarta-commons-modeler-0:2.0-3jpp_2rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: log4j-0:1.2.12-1jpp_1rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: mx4j-1:3.0.1-1jpp_4rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: pcsc-lite-0:1.3.3-3.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-ca-0:7.3.0-20.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-java-tools-0:7.3.0-10.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-kra-0:7.3.0-14.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-manage-0:7.3.0-19.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-native-tools-0:7.3.0-6.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-ocsp-0:7.3.0-13.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: rhpki-tks-0:7.3.0-13.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: tomcat5-0:5.5.23-0jpp_4rh.16
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: xerces-j2-0:2.7.1-1jpp_1rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Certificate System 7.3Fixed in: xml-commons-0:1.3.02-2jpp_1rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 2.1Fixed in: apache-0:1.3.27-14.ent
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: httpd-0:2.0.46-70.ent
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: httpd-0:2.0.52-38.ent.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: httpd-0:2.2.3-11.el5_1.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Proxy v 4.2 (RHEL 3)Fixed in: jabberd-0:2.0s10-3.37.rhn
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Proxy v 4.2 (RHEL 3)Fixed in: rhn-apache-0:1.3.27-36.rhn.rhel3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Proxy v 4.2 (RHEL 3)Fixed in: rhn-modperl-0:1.29-16.rhel3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Proxy v 4.2 (RHEL 4)Fixed in: jabberd-0:2.0s10-3.38.rhn
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Proxy v 4.2 (RHEL 4)Fixed in: rhn-apache-0:1.3.27-36.rhn.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Proxy v 4.2 (RHEL 4)Fixed in: rhn-modperl-0:1.29-16.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Proxy v 5.0Fixed in: jabberd-0:2.0s10-3.38.rhn
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Proxy v 5.0Fixed in: rhn-apache-0:1.3.27-36.rhn.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Proxy v 5.0Fixed in: rhn-modperl-0:1.29-16.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: jabberd-0:2.0s10-3.38.rhn
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: java-1.4.2-ibm-0:1.4.2.10-1jpp.2.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: jfreechart-0:0.9.20-3.rhn
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: openmotif21-0:2.1.30-11.RHEL4.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: perl-Crypt-CBC-0:2.24-1.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: rhn-apache-0:1.3.27-36.rhn.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: rhn-modjk-0:1.2.23-2rhn.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: rhn-modperl-0:1.29-16.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: rhn-modssl-0:2.8.12-8.rhn.10.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: tomcat5-0:5.0.30-0jpp_10rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: jabberd-0:2.0s10-3.37.rhn
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: java-1.4.2-ibm-0:1.4.2.10-1jpp.2.el3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: jfreechart-0:0.9.20-3.rhn
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: openmotif21-0:2.1.30-9.RHEL3.8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: perl-Crypt-CBC-0:2.24-1.el3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: rhn-apache-0:1.3.27-36.rhn.rhel3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: rhn-modjk-0:1.2.23-2rhn.rhel3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: rhn-modperl-0:1.29-16.rhel3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: rhn-modssl-0:2.8.12-8.rhn.10.rhel3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: tomcat5-0:5.0.30-0jpp_10rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: jabberd-0:2.0s10-3.38.rhn
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: java-1.4.2-ibm-0:1.4.2.10-1jpp.2.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: jfreechart-0:0.9.20-3.rhn
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: openmotif21-0:2.1.30-11.RHEL4.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: perl-Crypt-CBC-0:2.24-1.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: rhn-apache-0:1.3.27-36.rhn.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: rhn-modjk-0:1.2.23-2rhn.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: rhn-modperl-0:1.29-16.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: rhn-modssl-0:2.8.12-8.rhn.10.rhel4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: tomcat5-0:5.0.30-0jpp_10rh
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Web Application Stack for RHEL 4Fixed in: httpd-0:2.0.59-1.el4s1.10
View patch
redhatend of lifevia redhat_api
Product: Red Hat Directory Server 8Fixed in: httpd

Vendor Advisories (1)

redhatCVE-2007-5000Low

httpd: mod_imagemap XSS

Dec 11, 2007

References

docs.info.apple.com / article.html
Broken Link
h20000.www2.hp.com / bizsupport/TechSupport/Document.jsp
Broken Link
httpd.apache.org / security/vulnerabilities_13.html
Vendor Advisory
httpd.apache.org / security/vulnerabilities_20.html
Vendor Advisory
httpd.apache.org / security/vulnerabilities_22.html
Vendor Advisory
lists.apple.com / archives/security-announce/2008/Mar/msg00001.html
Broken LinkMailing ListThird Party Advisory
lists.apple.com / archives/security-announce/2008//May/msg00001.html
Broken LinkMailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2008-04/msg00004.html
Mailing ListThird Party Advisory
lists.vmware.com / pipermail/security-announce/2009/000062.html
Mailing ListThird Party Advisory
marc.info
Issue TrackingThird Party Advisory
secunia.com / advisories/28046
Broken LinkVendor Advisory
secunia.com / advisories/28073
Broken LinkVendor Advisory
secunia.com / advisories/28081
Broken Link
secunia.com / advisories/28196
Broken Link
secunia.com / advisories/28375
Broken Link
secunia.com / advisories/28467
Broken Link
secunia.com / advisories/28471
Broken Link
secunia.com / advisories/28525
Broken Link
secunia.com / advisories/28526
Broken Link
secunia.com / advisories/28607
Broken Link
secunia.com / advisories/28749
Broken Link
secunia.com / advisories/28750
Broken Link
secunia.com / advisories/28922
Broken Link
secunia.com / advisories/28977
Broken Link
secunia.com / advisories/29420
Broken Link
secunia.com / advisories/29640
Broken Link
secunia.com / advisories/29806
Broken Link
secunia.com / advisories/29988
Broken Link
secunia.com / advisories/30356
Broken Link
secunia.com / advisories/30430
Broken Link
secunia.com / advisories/30732
Broken Link
secunia.com / advisories/31142
Broken Link
secunia.com / advisories/32800
Broken Link
securitytracker.com / id
Broken LinkThird Party AdvisoryVDB Entry
exchange.xforce.ibmcloud.com / vulnerabilities/39001
Third Party AdvisoryVDB Entry
exchange.xforce.ibmcloud.com / vulnerabilities/39002
Third Party AdvisoryVDB Entry
slackware.com / security/viewer.php
Third Party Advisory
lists.apache.org / thread.html/54a42d4b01968df1117cea77fc53d6beb931c0e05936ad02af93e9ac%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/5df9bfb86a3b054bb985a45ff9250b0332c9ecc181eec232489e7f79%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/8d63cb8e9100f28a99429b4328e4e7cebce861d5772ac9863ba2ae6f%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/f7f95ac1cd9895db2714fa3ebaa0b94d0c6df360f742a40951384a53%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r0276683d8e1e07153fc8642618830ac0ade85b9ae0dc7b07f63bb8fc%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r2cb985de917e7da0848c440535f65a247754db8b2154a10089e4247b%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r57608dc51b79102f3952ae06f54d5277b649c86d6533dcd6a7d201f7%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r75cbe9ea3e2114e4271bbeca7aff96117b50c1b6eb7c4772b0337c1f%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r7dd6be4dc38148704f2edafb44a8712abaa3a2be120d6c3314d55919%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r84d043c2115176958562133d96d851495d712aa49da155d81f6733be%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r8828e649175df56f1f9e3919938ac7826128525426e2748f0ab62feb%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r9e8622254184645bc963a1d47c5d47f6d5a36d6f080d8d2c43b2b142%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r9ea3538f229874c80a10af473856a81fbf5f694cd7f471cc679ba70b%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/rafd145ba6cd0a4ced113a5823cdaff45aeb36eb09855b216401c66d6%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/rdca61ae990660bacb682295f2a09d34612b7bb5f457577fe17f4d064%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E
lists.apache.org / thread.html/rfbaf647d52c1cb843e726a0933f156366a806cead84fbd430951591b%40%3Ccvs.httpd.apache.org%3E
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9539
Third Party Advisory
sunsolve.sun.com / search/document.do
Broken Link
support.avaya.com / elmodocs2/security/ASA-2008-032.htm
Third Party Advisory
redhat.com / archives/fedora-package-announce/2008-February/msg00541.html
Third Party Advisory
redhat.com / archives/fedora-package-announce/2008-February/msg00562.html
Third Party Advisory
www-1.ibm.com / support/docview.wss
Broken Link
www-1.ibm.com / support/docview.wss
Third Party Advisory
www-1.ibm.com / support/docview.wss
Broken Link
www-1.ibm.com / support/docview.wss
Third Party Advisory
fujitsu.com / global/support/software/security/products-f/interstage-200801e.html
Third Party Advisory
mandriva.com / security/advisories
Broken Link
mandriva.com / security/advisories
Broken Link
mandriva.com / security/advisories
Broken Link
oracle.com / technetwork/topics/security/cpujuly2013-1899826.html
Third Party Advisory
osvdb.org / 39134
Broken Link
redhat.com / support/errata/RHSA-2008-0004.html
Third Party Advisory
redhat.com / support/errata/RHSA-2008-0005.html
Third Party Advisory
redhat.com / support/errata/RHSA-2008-0006.html
Third Party Advisory
redhat.com / support/errata/RHSA-2008-0007.html
Third Party Advisory
redhat.com / support/errata/RHSA-2008-0008.html
Third Party Advisory
redhat.com / support/errata/RHSA-2008-0009.html
Third Party Advisory
redhat.com / support/errata/RHSA-2008-0261.html
Third Party Advisory
securityfocus.com / archive/1/494428/100/0/threaded
Third Party AdvisoryVDB Entry
securityfocus.com / archive/1/498523/100/0/threaded
Third Party AdvisoryVDB Entry
securityfocus.com / archive/1/505990/100/0/threaded
Third Party AdvisoryVDB Entry
securityfocus.com / bid/26838
Third Party AdvisoryVDB Entry
ubuntu.com / usn/usn-575-1
Third Party Advisory
us-cert.gov / cas/techalerts/TA08-150A.html
Third Party AdvisoryUS Government Resource
vupen.com / english/advisories/2007/4201
Permissions Required
vupen.com / english/advisories/2007/4202
Permissions Required
vupen.com / english/advisories/2007/4301
Permissions Required
vupen.com / english/advisories/2008/0084
Permissions Required
vupen.com / english/advisories/2008/0178
Permissions Required
vupen.com / english/advisories/2008/0398
Permissions Required
vupen.com / english/advisories/2008/0809/references
Permissions Required
vupen.com / english/advisories/2008/0924/references
Permissions Required
vupen.com / english/advisories/2008/1224/references
Permissions Required
vupen.com / english/advisories/2008/1623/references
Permissions Required
vupen.com / english/advisories/2008/1697
Permissions Required
vupen.com / english/advisories/2008/1875/references
Permissions Required