CVE-2008-6570: XSS
Published Mar 31, 2009
·Updated
Cross-site scripting (XSS) vulnerability in the RSS reader in Cybozu Garoon 2.0.0 through 2.1.3 allows remote attackers to inject arbitrary web script or HTML via a crafted RSS feed.
Affected Software
11 affected components
Cybozu Garoon=2.1.0
Cybozu Garoon=2.0.2
Cybozu Garoon=2.0.4
Cybozu Garoon=2.0.6
Cybozu Garoon=2.1.3
Cybozu Garoon=2.0.5
Cybozu Garoon=2.0.3
Cybozu Garoon=2.1.1
Cybozu Garoon=2.0.1
Cybozu Garoon=2.1.2
Cybozu Garoon=2.0.0
Remediation
Patch Available
Event History
Mar 31, 2009
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:30 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-6570?
CVE-2008-6570 has a medium severity rating due to its ability to facilitate cross-site scripting attacks.
2
How do I fix CVE-2008-6570?
To fix CVE-2008-6570, upgrade Cybozu Garoon to version 2.1.4 or later.
3
Which versions of Cybozu Garoon are affected by CVE-2008-6570?
CVE-2008-6570 affects Cybozu Garoon versions 2.0.0 through 2.1.3.
4
What type of vulnerability is identified in CVE-2008-6570?
CVE-2008-6570 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2008-6570 be exploited remotely?
Yes, CVE-2008-6570 can be exploited remotely through a crafted RSS feed.