{"id":"DEBIAN-CVE-2012-3499","details":"Multiple cross-site scripting (XSS) vulnerabilities in the Apache HTTP Server 2.2.x before 2.2.24-dev and 2.4.x before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via vectors involving hostnames and URIs in the (1) mod_imagemap, (2) mod_info, (3) mod_ldap, (4) mod_proxy_ftp, and (5) mod_status modules.","modified":"2026-04-28T20:16:33.691350Z","published":"2013-02-26T16:55:01.033Z","upstream":["CVE-2012-3499"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2012-3499"}],"affected":[{"package":{"name":"apache2","ecosystem":"Debian:11","purl":"pkg:deb/debian/apache2?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2.22-13"}]}],"ecosystem_specific":{"urgency":"low"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2012-3499.json"}},{"package":{"name":"apache2","ecosystem":"Debian:12","purl":"pkg:deb/debian/apache2?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2.22-13"}]}],"ecosystem_specific":{"urgency":"low"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2012-3499.json"}},{"package":{"name":"apache2","ecosystem":"Debian:13","purl":"pkg:deb/debian/apache2?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2.22-13"}]}],"ecosystem_specific":{"urgency":"low"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2012-3499.json"}},{"package":{"name":"apache2","ecosystem":"Debian:14","purl":"pkg:deb/debian/apache2?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2.22-13"}]}],"ecosystem_specific":{"urgency":"low"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2012-3499.json"}}],"schema_version":"1.7.5"}