CVE-2008-0005 : Details

CVE-2008-0005

Cross-site Scripting
A03-Injection
2.65%V4
Network
2008-01-12
00h00 +00:00
2024-08-07
07h32 +00:00
Benachrichtigungen für ein CVE
Bleiben Sie über alle Änderungen zu einem bestimmten CVE informiert.
Benachrichtigungen verwalten

CVE-Beschreibungen

mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 encoding.

CVE-Informationen

Verwandte Schwachstellen

CWE-ID Name der Schwachstelle Source
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Metriken

Metriken Score Schweregrad CVSS Vektor Source
V2 4.3 AV:N/AC:M/Au:N/C:N/I:P/A:N nvd@nist.gov

EPSS

EPSS ist ein Bewertungsmodell, das die Wahrscheinlichkeit vorhersagt, dass eine Schwachstelle ausgenutzt wird.

EPSS-Score

Das EPSS-Modell liefert einen Wahrscheinlichkeitswert zwischen 0 und 1 (0 und 100%). Je höher der Score, desto größer die Wahrscheinlichkeit, dass eine Schwachstelle ausgenutzt wird.

EPSS-Perzentil

Das Perzentil wird verwendet, um CVEs nach ihrem EPSS-Score zu ranken. Ein CVE im 95. Perzentil gemäß seinem EPSS-Score ist beispielsweise mit größerer Wahrscheinlichkeit ausnutzbar als 95% der anderen CVEs. Das Perzentil dient somit zum Vergleich des EPSS-Scores eines CVEs mit dem anderer CVEs.

Products Mentioned

Configuraton 0

Apache>>Http_server >> Version From (including) 2.0.35 To (excluding) 2.0.63

Apache>>Http_server >> Version From (including) 2.2.0 To (excluding) 2.2.8

Configuraton 0

Fedoraproject>>Fedora >> Version 7

Fedoraproject>>Fedora >> Version 8

Configuraton 0

Canonical>>Ubuntu_linux >> Version 6.06

Canonical>>Ubuntu_linux >> Version 6.10

Canonical>>Ubuntu_linux >> Version 7.04

Canonical>>Ubuntu_linux >> Version 7.10

Referenzen

http://www.redhat.com/support/errata/RHSA-2008-0005.html
Tags : vendor-advisory, x_refsource_REDHAT
http://security.gentoo.org/glsa/glsa-200803-19.xml
Tags : vendor-advisory, x_refsource_GENTOO
http://secunia.com/advisories/28749
Tags : third-party-advisory, x_refsource_SECUNIA
http://marc.info/?l=bugtraq&m=125631037611762&w=2
Tags : vendor-advisory, x_refsource_HP
http://securityreason.com/securityalert/3526
Tags : third-party-advisory, x_refsource_SREASON
http://marc.info/?l=bugtraq&m=124654546101607&w=2
Tags : vendor-advisory, x_refsource_HP
http://marc.info/?l=bugtraq&m=130497311408250&w=2
Tags : vendor-advisory, x_refsource_HP
http://securityreason.com/achievement_securityalert/49
Tags : third-party-advisory, x_refsource_SREASONRES
http://www.securityfocus.com/bid/27234
Tags : vdb-entry, x_refsource_BID
http://secunia.com/advisories/28526
Tags : third-party-advisory, x_refsource_SECUNIA
http://www.redhat.com/support/errata/RHSA-2008-0006.html
Tags : vendor-advisory, x_refsource_REDHAT
http://www.redhat.com/support/errata/RHSA-2008-0007.html
Tags : vendor-advisory, x_refsource_REDHAT
http://marc.info/?l=bugtraq&m=125631037611762&w=2
Tags : vendor-advisory, x_refsource_HP
http://www.securitytracker.com/id?1019185
Tags : vdb-entry, x_refsource_SECTRACK
http://www.redhat.com/support/errata/RHSA-2008-0008.html
Tags : vendor-advisory, x_refsource_REDHAT
http://www.redhat.com/support/errata/RHSA-2008-0009.html
Tags : vendor-advisory, x_refsource_REDHAT
http://www.mandriva.com/security/advisories?name=MDVSA-2008:014
Tags : vendor-advisory, x_refsource_MANDRIVA
http://secunia.com/advisories/29420
Tags : third-party-advisory, x_refsource_SECUNIA
http://marc.info/?l=bugtraq&m=130497311408250&w=2
Tags : vendor-advisory, x_refsource_HP
http://secunia.com/advisories/28467
Tags : third-party-advisory, x_refsource_SECUNIA
http://secunia.com/advisories/29348
Tags : third-party-advisory, x_refsource_SECUNIA
http://www.redhat.com/support/errata/RHSA-2008-0004.html
Tags : vendor-advisory, x_refsource_REDHAT
http://secunia.com/advisories/28607
Tags : third-party-advisory, x_refsource_SECUNIA
http://www.mandriva.com/security/advisories?name=MDVSA-2008:015
Tags : vendor-advisory, x_refsource_MANDRIVA
http://marc.info/?l=bugtraq&m=124654546101607&w=2
Tags : vendor-advisory, x_refsource_HP
http://secunia.com/advisories/28471
Tags : third-party-advisory, x_refsource_SECUNIA
http://www.ubuntu.com/usn/usn-575-1
Tags : vendor-advisory, x_refsource_UBUNTU
http://secunia.com/advisories/29640
Tags : third-party-advisory, x_refsource_SECUNIA
http://secunia.com/advisories/28977
Tags : third-party-advisory, x_refsource_SECUNIA
http://secunia.com/advisories/30732
Tags : third-party-advisory, x_refsource_SECUNIA
http://secunia.com/advisories/35650
Tags : third-party-advisory, x_refsource_SECUNIA
http://www.mandriva.com/security/advisories?name=MDVSA-2008:016
Tags : vendor-advisory, x_refsource_MANDRIVA