Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2008-2025


Cross-site scripting (XSS) vulnerability in Apache Struts before 1.2.9-162.31.1 on SUSE Linux Enterprise (SLE) 11, before 1.2.9-108.2 on SUSE openSUSE 10.3, before 1.2.9-198.2 on SUSE openSUSE 11.0, and before 1.2.9-162.163.2 on SUSE openSUSE 11.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "insufficient quoting of parameters."


Published

2009-04-09T15:08:35.483

Last Modified

2025-04-09T00:30:58.490

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache struts 1.0.2 Yes
Application apache struts 1.1 Yes
Application apache struts 1.2.4 Yes
Application apache struts 1.2.7 Yes
Application apache struts 1.2.8 Yes
Operating System novell suse_linux 11 No
Operating System opensuse opensuse 10.3 No
Operating System opensuse opensuse 11.0 No
Operating System opensuse opensuse 11.1 No

References