First published: Fri Nov 14 2008(Updated: )
Cross-site scripting (XSS) vulnerability in the HTTP Protocol Stack (HTTPSTK) in Novell eDirectory before 8.8 SP3 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microfocus eDirectory | =8.7.3.9 | |
Microfocus eDirectory | =8.6.2 | |
Microfocus eDirectory | =8.5.27 | |
Microfocus eDirectory | =8.7.3-sp5 | |
Microfocus eDirectory | =8.7 | |
Microfocus eDirectory | =8.8 | |
Microfocus eDirectory | =8.8.1 | |
Microfocus eDirectory | =8.8 | |
Microfocus eDirectory | =8.0 | |
Microfocus eDirectory | =8.7.3.9 | |
Microfocus eDirectory | =8.7.3 | |
Microfocus eDirectory | =8.7.3-sp4 | |
Microfocus eDirectory | =8.8 | |
Microfocus eDirectory | =8.8 | |
Microfocus eDirectory | =8.7.3-sp1 | |
Microfocus eDirectory | =8.5.12a | |
Microfocus eDirectory | =8.8.1 | |
Microfocus eDirectory | =8.7.3-sp8 | |
Microfocus eDirectory | <=8.8 | |
Microfocus eDirectory | =8.8.1 | |
Microfocus eDirectory | =8.7.3.10 | |
Microfocus eDirectory | =8.8.2 | |
Microfocus eDirectory | ||
Microfocus eDirectory | =8.7.3.9 | |
Microfocus eDirectory | =8.8.2 | |
Microfocus eDirectory | =8.8.2 | |
Microfocus eDirectory | =8.7.3-sp3 | |
Microfocus eDirectory | =8.8.2 | |
Microfocus eDirectory | =8.7.3-sp6 | |
Microfocus eDirectory | =8.7.3.9 | |
Microfocus eDirectory | =8.7.3.8_presp9 | |
Microfocus eDirectory | =8.8.2 | |
Microfocus eDirectory | =8.7.1 | |
Microfocus eDirectory | =8.7.1-sp1 | |
Microfocus eDirectory | =8.7.3-sp7 | |
Microfocus eDirectory | =8.7.3.8 | |
Microfocus eDirectory | =8.8.1 | |
Microfocus eDirectory | =8.8 | |
Microfocus eDirectory | =8.8.1 | |
Microfocus eDirectory | =8.7.3-sp2 | |
Microfocus eDirectory | =8.7.3-sp9 | |
Microfocus eDirectory | =8.7.3.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2008-5093 is classified as high due to the potential for remote code execution via XSS.
To fix CVE-2008-5093, you should upgrade to Novell eDirectory version 8.8 SP3 or later, which includes the necessary patches.
CVE-2008-5093 affects multiple versions of Novell eDirectory, specifically versions prior to 8.8 SP3.
The potential impacts of CVE-2008-5093 include unauthorized access to data and the ability to execute arbitrary scripts in the context of the user's session.
Yes, CVE-2008-5093 can be exploited remotely, allowing attackers to inject arbitrary web scripts or HTML.