CVE-2008-7220: XSS
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-7220 to the following vulnerability:
Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before 1.6.0.2 allows attackers to make "cross-site ajax requests" via unknown vectors.
References: ------------ http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-7220 http://github.com/sstephenson/prototype/blob/master/CHANGELOG http://osvdb.org/46312
Upstream patch: --------------- git clone git://github.com/sstephenson/prototype.git git show 02cc9992e915c024650ddc77a91064f7a4252914
The relevant file in WordPress source rpm package (F10) is: ------------------------------------------------------------ BUILD/wordpress/wp-includes/js/prototype.js
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-7220?
CVE-2008-7220 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2008-7220?
To remediate CVE-2008-7220, upgrade the Prototype JavaScript framework to version 1.6.0.2 or later.
What versions of Prototype are affected by CVE-2008-7220?
CVE-2008-7220 affects all versions of the Prototype JavaScript framework before 1.6.0.2.
Is CVE-2008-7220 exploitable remotely?
Yes, CVE-2008-7220 can be exploited remotely by attackers through cross-site scripting.
What software is impacted by CVE-2008-7220?
CVE-2008-7220 impacts the Prototype JavaScript framework and specific versions of Debian Linux.