First published: Tue May 13 2008(Updated: )
Cross-site scripting (XSS) vulnerability in IBM Lotus Quickr 8.1 before Hotfix 5 for Windows and AIX, and before Hotfix 3 for i5/OS, allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to "WYSIWYG editors."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM AIX | ||
IBM i | ||
Microsoft Windows NT | ||
IBM Lotus Quickr | =8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2163 is classified with a medium severity due to the potential for cross-site scripting attacks.
To fix CVE-2008-2163, update IBM Lotus Quickr to version 8.1 Hotfix 5 or later.
CVE-2008-2163 allows remote attackers to inject arbitrary web scripts or HTML into affected applications.
CVE-2008-2163 affects IBM Lotus Quickr version 8.1 prior to Hotfix 5.
Testing is advised to verify if systems are running affected versions of IBM Lotus Quickr that may be vulnerable to CVE-2008-2163.