4.3

CVE-2008-7092

Exploit
Multiple cross-site scripting (XSS) vulnerabilities in Unica Affinium Campaign 7.2.1.0.55 allow remote attackers to inject arbitrary web script or HTML via a Javascript event in the (1) url, (2) PageName, and (3) title parameters in a CustomBookMarkLink action to Campaign/Campaign; (4) a Javascript event in the displayIcon parameter to Campaign/updateOfferTemplateSubmit.do (aka the templates web page); (5) crafted input to Campaign/CampaignListener (aka the listener server), which is not properly handled when displaying the status log; and (6) id parameter to Campaign/campaignDetails.do, (7) id parameter to Campaign/offerDetails.do, (8) function parameter to Campaign/Campaign, (9) sessionID parameter to Campaign/runAllFlowchart.do, (10) id parameter in an edit action to Campaign/updateOfferTemplatePage.do, (11) Frame parameter in a LoadFrame action to Campaign/Campaign, (12) affiniumUserName parameter to manager/jsp/test.jsp, (13) affiniumUserName parameter to Campaign/main.do, and possibly other vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
UnicaAffinium Campaign Version7.2.1.0.55
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.77% 0.753
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

http://secunia.com/advisories/31280
Vendor Advisory
http://www.osvdb.org/47520
Exploit
http://www.osvdb.org/47521
Exploit
http://www.osvdb.org/47522
Exploit
http://www.osvdb.org/47523
Exploit
http://www.osvdb.org/47524
Exploit
http://www.osvdb.org/47525
Exploit
http://www.osvdb.org/47526
http://www.osvdb.org/47528
http://www.osvdb.org/47530
Exploit
http://www.portcullis.co.uk/286.php
Exploit
http://www.portcullis.co.uk/288.php
Exploit
http://www.portcullis.co.uk/289.php
Exploit
http://www.portcullis.co.uk/290.php
Exploit
http://www.securityfocus.com/bid/30433
https://exchange.xforce.ibmcloud.com/vulnerabilities/44072
https://exchange.xforce.ibmcloud.com/vulnerabilities/44073
https://exchange.xforce.ibmcloud.com/vulnerabilities/44074