CVE-2008-2163: XSS
Published May 13, 2008
·Updated
Cross-site scripting (XSS) vulnerability in IBM Lotus Quickr 8.1 before Hotfix 5 for Windows and AIX, and before Hotfix 3 for i5/OS, allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to "WYSIWYG editors."
Affected Software
4 affected components
IBM AIX
IBM I5os
Microsoft Windows NT
IBM Lotus Quickr=8.1
Remediation
Patch Available
Event History
May 13, 2008
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
05:20 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-2163?
CVE-2008-2163 is classified with a medium severity due to the potential for cross-site scripting attacks.
2
How do I fix CVE-2008-2163?
To fix CVE-2008-2163, update IBM Lotus Quickr to version 8.1 Hotfix 5 or later.
3
What types of attacks are possible due to CVE-2008-2163?
CVE-2008-2163 allows remote attackers to inject arbitrary web scripts or HTML into affected applications.
4
Which software versions are affected by CVE-2008-2163?
CVE-2008-2163 affects IBM Lotus Quickr version 8.1 prior to Hotfix 5.
5
Is laboratory testing required to evaluate CVE-2008-2163?
Testing is advised to verify if systems are running affected versions of IBM Lotus Quickr that may be vulnerable to CVE-2008-2163.