CVE-2008-0868: XSS
Cross-site scripting (XSS) vulnerability in Groupspace in BEA WebLogic Portal 10.0 and 9.2 through Maintenance Pack 1 allows remote authenticated users to inject arbitrary web script or HTML via unknown vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0868?
CVE-2008-0868 is classified as a moderate severity cross-site scripting vulnerability.
How do I fix CVE-2008-0868?
To fix CVE-2008-0868, ensure that you upgrade to the latest version of BEA WebLogic Portal that addresses this vulnerability.
Who is affected by CVE-2008-0868?
CVE-2008-0868 affects users of BEA WebLogic Portal versions 10.0 and 9.2 through Maintenance Pack 1.
What type of attack can CVE-2008-0868 enable?
CVE-2008-0868 can enable remote authenticated users to inject arbitrary web script or HTML into affected portals.
Is CVE-2008-0868 a client-side or server-side vulnerability?
CVE-2008-0868 is primarily a client-side vulnerability as it involves executing malicious scripts in the user's browser.