4.3

CVE-2008-2929

Multiple cross-site scripting (XSS) vulnerabilities in the adminutil library in the Directory Server Administration Express and Directory Server Gateway (DSGW) web interface in Red Hat Directory Server 7.1 before SP7 and 8 EL4 and EL5, and Fedora Directory Server, allow remote attackers to inject arbitrary web script or HTML via input values that use % (percent) escaping.

Data is provided by the National Vulnerability Database (NVD)
RedhatDirectory Server Version7.1 Updatesp1
RedhatDirectory Server Version7.1 Updatesp2
RedhatDirectory Server Version7.1 Updatesp3
RedhatDirectory Server Version7.1 Updatesp4
RedhatDirectory Server Version7.1 Updatesp5
RedhatDirectory Server Version7.1 Updatesp6
RedhatDirectory Server Version8.0 Updateel4
RedhatDirectory Server Version8.0 Updateel5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.63% 0.678
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.