4.3
CVSSv2

CVE-2008-0919

Published: 22/02/2008 Updated: 15/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in session/login.php in Open Source Security Information Management (OSSIM) 0.9.9 rc5 and previous versions allows remote malicious users to inject arbitrary web script or HTML via the dest parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

open source security information management os-sim 0.3.1alpha

open source security information management os-sim 0.3alpha

open source security information management os-sim 0.7.1

open source security information management os-sim 0.8

open source security information management os-sim 0.9.7

open source security information management os-sim 0.9.8

open source security information management os-sim 0.5.1

open source security information management os-sim 0.5.2

open source security information management os-sim 0.9

open source security information management os-sim 0.9.1

open source security information management os-sim 0.9.9_rc1

open source security information management os-sim 0.9.9_rc2

open source security information management os-sim 0.1alpha

open source security information management os-sim 0.2alpha

open source security information management os-sim 0.6.3

open source security information management os-sim 0.7

open source security information management os-sim 0.9.4

open source security information management os-sim 0.9.5

open source security information management os-sim 0.9.6

open source security information management os-sim 0.6

open source security information management os-sim 0.6.2

open source security information management os-sim 0.9.2

open source security information management os-sim 0.9.3

open source security information management os-sim 0.9.9_rc3

open source security information management os-sim 0.9.9_rc4

Exploits

Application: OSSIM wwwossimnet Version: 099rc5 Note: it is possible that the problem affects also earlier OSSIM versions Platforms: Linux Bug: SQL injection, Cross Site Scripting Exploitation: remote Date: 21 Feb 2008 Author: Marcin Kopec E-mail: marcin(dot)kopec(at)hotmail(dot)com --------------------------------------- 1) Introducti ...