CVE-2008-0925: XSS
Cross-site scripting (XSS) vulnerability in the iMonitor interface in Novell eDirectory 8.7.3.x before 8.7.3 sp10, and 8.8.x before 8.8.2 ftf2, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters that are used within "error messages of the HTTP stack."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0925?
CVE-2008-0925 has a medium severity rating due to its potential for cross-site scripting attacks that could compromise user data.
How do I fix CVE-2008-0925?
To fix CVE-2008-0925, upgrade Novell eDirectory to version 8.7.3 sp10 or later for the 8.7 series, or 8.8.2 ftf2 or later for the 8.8 series.
Which versions of Novell eDirectory are affected by CVE-2008-0925?
CVE-2008-0925 affects Novell eDirectory versions 8.7.3.x prior to 8.7.3 sp10 and 8.8.x prior to 8.8.2 ftf2.
What type of vulnerability is CVE-2008-0925?
CVE-2008-0925 is classified as a cross-site scripting (XSS) vulnerability.
Who can exploit CVE-2008-0925?
CVE-2008-0925 can be exploited by remote attackers who can inject arbitrary web scripts through unspecified parameters.