Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.
- http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html
- https://github.com/ARPSyndicate/cve-scores