4.3
CVSSv2

CVE-2008-4918

Published: 04/11/2008 Updated: 17/06/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in SonicWALL SonicOS Enhanced prior to 4.0.1.1, as used in SonicWALL Pro 2040 and TZ 180 and 190, allows remote malicious users to inject arbitrary web script or HTML into arbitrary web sites via a URL to a site that is blocked based on content filtering, which is not properly handled in the CFS block page, aka "universal website hijacking."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sonicwall sonicos_enhanced

Exploits

source: wwwsecurityfocuscom/bid/31998/info SonicWALL Content Filtering is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input when displaying URI address data in a blocked-site error page An attacker may leverage this issue to execute arbitrary script code in the browser o ...