CVE-2000-1205

Cross site scripting vulnerabilities in Apache 1.3.0 through 1.3.11 allow remote attackers to execute script as other web site visitors via (1) the printenv CGI (printenv.pl), which does not encode its output, (2) pages generated by the ap_send_error_response function such as a default 404, which does not add an explicit charset, or (3) various messages that are generated by certain Apache modules or core code. NOTE: the printenv issue might still exist for web browsers that can render text/plain content types as HTML, such as Internet Explorer, but CVE regards this as a design limitation of those browsers, not Apache. The printenv.pl/acuparam vector, discloser on 20070724, is one such variant.

Published: 2000-02-01 Last update: 2026-06-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2000-1205 is rated Moderate Risk (56.3/100): CVSS Medium severity, with high exploitation likelihood (EPSS 23.46%, 97th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. EPSS rose +17.76% over the last day, indicating growing attacker interest. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2000-1205

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 5.70% 23.46% +17.76%
2 2025-12-28 12.34% 5.70% -6.64%
3 2025-12-27 12.34%

Full EPSS history (16 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2000-1205

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
4.3 2.0 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:N)
No confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:N)
No availability impact.
8.6 2.9 [email protected]

Weakness enumeration for CVE-2000-1205

Vendor comments (NVD) for CVE-2000-1205

  • Apache (2008-07-02T00:00:00)

    Fixed in Apache HTTP Server 1.3.12: http://httpd.apache.org/security/vulnerabilities_13.html

Affected software / configurations for CVE-2000-1205

Vendor Product Version Raw CPE
apache http_server 1.3.0 cpe:2.3:a:apache:http_server:1.3.0:*:*:*:*:*:*:*
apache http_server 1.3.1 cpe:2.3:a:apache:http_server:1.3.1:*:*:*:*:*:*:*
apache http_server 1.3.2 cpe:2.3:a:apache:http_server:1.3.2:*:*:*:*:*:*:*
apache http_server 1.3.3 cpe:2.3:a:apache:http_server:1.3.3:*:*:*:*:*:*:*
apache http_server 1.3.4 cpe:2.3:a:apache:http_server:1.3.4:*:*:*:*:*:*:*
apache http_server 1.3.5 cpe:2.3:a:apache:http_server:1.3.5:*:*:*:*:*:*:*
apache http_server 1.3.6 cpe:2.3:a:apache:http_server:1.3.6:*:*:*:*:*:*:*
apache http_server 1.3.7 cpe:2.3:a:apache:http_server:1.3.7:*:*:*:*:*:*:*
apache http_server 1.3.8 cpe:2.3:a:apache:http_server:1.3.8:*:*:*:*:*:*:*
apache http_server 1.3.9 cpe:2.3:a:apache:http_server:1.3.9:*:*:*:*:*:*:*
apache http_server 1.3.10 cpe:2.3:a:apache:http_server:1.3.10:*:*:*:*:*:*:*
apache http_server 1.3.11 cpe:2.3:a:apache:http_server:1.3.11:*:*:*:*:*:*:*

References for CVE-2000-1205

URL Tags
http://archive.cert.uni-stuttgart.de/bugtraq/2002/12/msg00243.html
http://archives.neohapsis.com/archives/bugtraq/2002-12/0233.html
http://httpd.apache.org/info/css-security/apache_specific.html Patch Vendor Advisory
http://marc.info/?l=bugtraq&m=118529436424127&w=2
https://exchange.xforce.ibmcloud.com/vulnerabilities/10938
https://exchange.xforce.ibmcloud.com/vulnerabilities/35597
https://lists.apache.org/thread.html/r5419c9ba0951ef73a655362403d12bb8d10fab38274deb3f005816f5%40%3Ccvs.httpd.apache.org%3E
https://lists.apache.org/thread.html/r5f9c22f9c28adbd9f00556059edc7b03a5d5bb71d4bb80257c0d34e4%40%3Ccvs.httpd.apache.org%3E
https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E
https://lists.apache.org/thread.html/rf2f0f3611f937cf6cfb3b4fe4a67f69885855126110e1e3f2fb2728e%40%3Ccvs.httpd.apache.org%3E
https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E
cvelogic Threat Intelligence