First published: Wed Jan 23 2008(Updated: )
Common Vulnerabilities and Exposures assigned an identifier <a href="https://access.redhat.com/security/cve/CVE-2008-7220">CVE-2008-7220</a> to the following vulnerability: Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before 1.6.0.2 allows attackers to make "cross-site ajax requests" via unknown vectors. References: ------------ <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-7220">http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-7220</a> <a href="http://github.com/sstephenson/prototype/blob/master/CHANGELOG">http://github.com/sstephenson/prototype/blob/master/CHANGELOG</a> <a href="http://osvdb.org/46312">http://osvdb.org/46312</a> Upstream patch: --------------- git clone git://github.com/sstephenson/prototype.git git show 02cc9992e915c024650ddc77a91064f7a4252914 The relevant file in WordPress source rpm package (F10) is: ------------------------------------------------------------ BUILD/wordpress/wp-includes/js/prototype.js
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Prototypejs Prototype | <1.6.0.2 | |
Debian Debian Linux | =5.0 | |
Debian Debian Linux | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.