First published: Wed Jun 18 2008(Updated: )
Cross-site scripting (XSS) vulnerability in the iMonitor interface in Novell eDirectory 8.7.3.x before 8.7.3 sp10, and 8.8.x before 8.8.2 ftf2, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters that are used within "error messages of the HTTP stack."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell Edirectory | =8.8 | |
Novell Edirectory | =8.8.1 | |
Novell Edirectory | =8.7.3.9 | |
Novell Edirectory | =8.8 | |
Novell Edirectory | =8.8 | |
Novell Edirectory | =8.8.1 | |
Novell Edirectory | =8.8.1 | |
Novell Edirectory | =8.7.3.9 | |
Novell Edirectory | =8.8.2 | |
Novell Edirectory | =8.8.2 | |
Novell Edirectory | =8.8.2 | |
Novell Edirectory | =8.7.3.9 | |
Novell Edirectory | =8.8.2 | |
Novell Edirectory | =8.8 | |
Novell Edirectory | =8.8.1 | |
Novell Edirectory | =8.7.3.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0925 has a medium severity rating due to its potential for cross-site scripting attacks that could compromise user data.
To fix CVE-2008-0925, upgrade Novell eDirectory to version 8.7.3 sp10 or later for the 8.7 series, or 8.8.2 ftf2 or later for the 8.8 series.
CVE-2008-0925 affects Novell eDirectory versions 8.7.3.x prior to 8.7.3 sp10 and 8.8.x prior to 8.8.2 ftf2.
CVE-2008-0925 is classified as a cross-site scripting (XSS) vulnerability.
CVE-2008-0925 can be exploited by remote attackers who can inject arbitrary web scripts through unspecified parameters.