VulnerabilityModified
CVE-2008-7266
Cross-site scripting (XSS) vulnerability in an unspecified Shockwave Flash file in RSA Adaptive Authentication 2.x and 5.7.x allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
MEDIUM 4.3EPSS 1.13%
Does this matter?
Lower severity and a low EPSS score (1.13%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in an unspecified Shockwave Flash file in RSA Adaptive Authentication 2.x and 5.7.x allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.13% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- rsa/adaptive authentication
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/42332Vendor Advisory
- http://www.securityfocus.com/archive/1/514869/100/0/threaded
- http://www.securitytracker.com/id?1024775
- http://www.vupen.com/english/advisories/2010/3055Vendor Advisory
- https://knowledge.rsasecurity.com/scolcms/set.aspx?id=8192
- http://secunia.com/advisories/42332Vendor Advisory
- http://www.securityfocus.com/archive/1/514869/100/0/threaded
- http://www.securitytracker.com/id?1024775
- http://www.vupen.com/english/advisories/2010/3055Vendor Advisory
- https://knowledge.rsasecurity.com/scolcms/set.aspx?id=8192
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.