VulnerabilityModified
CVE-2008-2462
Cross-site scripting (XSS) vulnerability in the viewfile documentation command in Caucho Resin before 3.0.25, and 3.1.x before 3.1.4, allows remote attackers to inject arbitrary web script or HTML via the file parameter.
MEDIUM 4.3EPSS 2.85%
Does this matter?
Lower severity and a low EPSS score (2.85%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in the viewfile documentation command in Caucho Resin before 3.0.25, and 3.1.x before 3.1.4, allows remote attackers to inject arbitrary web script or HTML via the file parameter.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 2.85% probability · 86th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- caucho/resin
- Source
- cret@cert.org
References
- http://secunia.com/advisories/30845Third Party Advisory
- http://www.caucho.com/resin/changes/changes-31.xtp#3.1.4%20-%20Dec%205%2C%202007
- http://www.kb.cert.org/vuls/id/305208Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/29948Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1020372Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2008/1930/referencesThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43367Third Party Advisory, VDB Entry
- http://secunia.com/advisories/30845Third Party Advisory
- http://www.caucho.com/resin/changes/changes-31.xtp#3.1.4%20-%20Dec%205%2C%202007
- http://www.kb.cert.org/vuls/id/305208Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/29948Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1020372Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2008/1930/referencesThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43367Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.