4.3
CVE-2008-5095
- EPSS 1.16%
- Veröffentlicht 14.11.2008 19:20:54
- Zuletzt bearbeitet 16.06.2026 22:59:14
- Erkennungen
Cross-site scripting (XSS) vulnerability in the Novell User Application 3.0.1, 3.5.0, and 3.5.1; and Identity Manager Roles Based Provisioning Module 3.6.0 and 3.6.1 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Novell ≫ Identity Manager Roles Based Provisioning Module Version 3.6.0
Novell ≫ Identity Manager Roles Based Provisioning Module Version 3.6.1
Novell ≫ User Application Version 3.0.1
Novell ≫ User Application Version 3.5.0
Novell ≫ User Application Version 3.5.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.16% | 0.631 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
http://www.securityfocus.com/bid/30947
http://www.novell.com/support/viewContent.do?externalId=7001157&sliceId=1
http://www.securitytracker.com/id?1020792
http://www.securitytracker.com/id?1020793