CVE-2008-0694: XSS
Published Feb 12, 2008
·Updated
Cross-site scripting (XSS) vulnerability in the HTTP Server in IBM OS/400 V5R3M0 and V5R4M0 allows remote attackers to inject arbitrary web script or HTML via the Expect HTTP header.
Affected Software
2 affected components
IBM Os 400=v5r3m0
IBM Os 400=v5r4m0
Event History
Feb 12, 2008
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-0694?
CVE-2008-0694 has a moderate severity level due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2008-0694?
To fix CVE-2008-0694, apply the latest security patches provided for IBM OS/400 versions V5R3M0 and V5R4M0.
3
Which versions of IBM OS/400 are affected by CVE-2008-0694?
CVE-2008-0694 specifically affects IBM OS/400 versions V5R3M0 and V5R4M0.
4
What type of vulnerability is CVE-2008-0694?
CVE-2008-0694 is a cross-site scripting (XSS) vulnerability that allows the injection of arbitrary web scripts or HTML.
5
Can CVE-2008-0694 be exploited remotely?
Yes, CVE-2008-0694 can be exploited remotely by attackers through the manipulation of the Expect HTTP header.