CVE-2008-0354: XSS
Cross-site scripting (XSS) vulnerability in the chat client in IBM Lotus Sametime 7.5 and 7.5.1 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted message, which triggers code execution after a mouseover event initiated by the victim.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0354?
CVE-2008-0354 is classified as a medium severity vulnerability due to the potential for user-assisted exploitation.
How do I fix CVE-2008-0354?
To mitigate CVE-2008-0354, updating IBM Lotus Sametime to the latest available version is recommended.
Who is affected by CVE-2008-0354?
CVE-2008-0354 affects users of IBM Lotus Sametime versions 7.5 and 7.5.1.
What type of attack is CVE-2008-0354 associated with?
CVE-2008-0354 is associated with a cross-site scripting (XSS) attack that can occur through crafted messages.
How can attackers exploit CVE-2008-0354?
Attackers can exploit CVE-2008-0354 by sending users a crafted message that executes arbitrary web scripts upon mouseover.