← Back

CVE-2008-2025

nvd nist
Published: Apr 9, 2009Modified: Apr 23, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Cross-site scripting (XSS) vulnerability in Apache Struts before 1.2.9-162.31.1 on SUSE Linux Enterprise (SLE) 11, before 1.2.9-108.2 on SUSE openSUSE 10.3, before 1.2.9-198.2 on SUSE openSUSE 11.0, and before 1.2.9-162.163.2 on SUSE openSUSE 11.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "insufficient quoting of parameters."

Affected (5)

Products: Apache: Struts
1 product
Struts
Configuration A
5 vulnerable · 4 platform
Vulnerable SoftwareAffected Versions
Apache
Version 1.0.2
Version 1.1
Version 1.2.4
Version 1.2.7
Version 1.2.8
Running on/withPlatform Versions
Novell
Suse Linux
Version 11
Opensuse
Opensuse
Version 10.3
Opensuse
Opensuse
Version 11.0
Opensuse
Opensuse
Version 11.1

References (16)

Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.