CVE-2008-2025: XSS
Cross-site scripting (XSS) vulnerability in Apache Struts before 1.2.9-162.31.1 on SUSE Linux Enterprise (SLE) 11, before 1.2.9-108.2 on SUSE openSUSE 10.3, before 1.2.9-198.2 on SUSE openSUSE 11.0, and before 1.2.9-162.163.2 on SUSE openSUSE 11.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "insufficient quoting of parameters."
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2008-2025?
CVE-2008-2025 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2008-2025?
To fix CVE-2008-2025, upgrade Apache Struts to version 1.2.9-162.31.1 or later.
What versions of Apache Struts are affected by CVE-2008-2025?
Affected versions include Apache Struts 1.0.2, 1.1, 1.2.4, 1.2.7, and 1.2.8.
What platforms are vulnerable to CVE-2008-2025?
Vulnerable platforms include SUSE Linux Enterprise 11, SUSE openSUSE 10.3, 11.0, and 11.1.
What type of attack does CVE-2008-2025 allow?
CVE-2008-2025 allows remote attackers to inject arbitrary web scripts into web pages.