Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-0919

Overview

Vulnerability Score 4.3 4.3
CVE Id CVE-2008-0919
Last Modified 19 Sep 2009 01:14:36
Published 22 Feb 2008 06:44:00
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2008-0919

Summary

Cross-site scripting (XSS) vulnerability in session/login.php in Open Source Security Information Management (OSSIM) 0.9.9 rc5 and earlier allows remote attackers to inject arbitrary web script or HTML via the dest parameter.

Vulnerable Systems

Application

  • Open Source Security Information Management Os-sim 0.1alpha

  • Open Source Security Information Management Os-sim 0.2alpha

  • Open Source Security Information Management Os-sim 0.3.1alpha

  • Open Source Security Information Management Os-sim 0.3alpha

  • Open Source Security Information Management Os-sim 0.5.1

  • Open Source Security Information Management Os-sim 0.5.2

  • Open Source Security Information Management Os-sim 0.6

  • Open Source Security Information Management Os-sim 0.6.2

  • Open Source Security Information Management Os-sim 0.6.3

  • Open Source Security Information Management Os-sim 0.7

  • Open Source Security Information Management Os-sim 0.7.1

  • Open Source Security Information Management Os-sim 0.8

  • Open Source Security Information Management Os-sim 0.9

  • Open Source Security Information Management Os-sim 0.9.1

  • Open Source Security Information Management Os-sim 0.9.2

  • Open Source Security Information Management Os-sim 0.9.3

  • Open Source Security Information Management Os-sim 0.9.4

  • Open Source Security Information Management Os-sim 0.9.5

  • Open Source Security Information Management Os-sim 0.9.6

  • Open Source Security Information Management Os-sim 0.9.7

  • Open Source Security Information Management Os-sim 0.9.8

  • Open Source Security Information Management Os-sim 0.9.9 Rc1

  • Open Source Security Information Management Os-sim 0.9.9 Rc2

  • Open Source Security Information Management Os-sim 0.9.9 Rc3

  • Open Source Security Information Management Os-sim 0.9.9 Rc4


References

BID - 27929

BUGTRAQ - 20080225 Re: Re: SQL-injection, XSS in OSSIM (Open Source Security Information Management)

BUGTRAQ - 20080221 SQL-injection, XSS in OSSIM (Open Source Security Information Management)

BUGTRAQ - 20080222 Re: SQL-injection, XSS in OSSIM (Open Source Security Information Management)

MILW0RM - 5171

SECUNIA - 29046

OSVDB - 42006

SREASON - 3689


Last Updated: 27 May 2016 10:46:58