7.5
CVSSv2

CVE-2008-7220

Published: 13/09/2009 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Unspecified vulnerability in Prototype JavaScript framework (prototypejs) prior to 1.6.0.2 allows malicious users to make "cross-site ajax requests" via unknown vectors.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

prototypejs prototype

debian debian linux 5.0

debian debian linux 6.0

Vendor Advisories

Debian Bug report logs - #555217 auth2db: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities Package: auth2db; Maintainer for auth2db is Ulises Vitulli <dererk@debianorg>; Source for auth2db is src:auth2db (PTS, buildd, popcon) Reported by: Michael Gilbert <michaelsgilbert@gmailcom> Date: Mon, 9 Nov 200 ...
Debian Bug report logs - #559103 CVE-2009-4055: RTP Remote Crash Vulnerability Package: asterisk; Maintainer for asterisk is Debian VoIP Team <pkg-voip-maintainers@listsaliothdebianorg>; Source for asterisk is src:asterisk (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Tue, 1 Dec 200 ...
Debian Bug report logs - #522528 AST-2009-003: SIP responses expose valid usernames Package: asterisk; Maintainer for asterisk is Debian VoIP Team <pkg-voip-maintainers@listsaliothdebianorg>; Source for asterisk is src:asterisk (PTS, buildd, popcon) Reported by: Tzafrir Cohen <tzafrircohen@xorcomcom> Date: Sat, ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> dotCMS v511 Vulnerabilities <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: John Martinelli &lt;john () ...

Github Repositories

repository for vulnerability check bootstrap: CVE-2018-14041 jQuery: CVE-2015-9251 prototypejs: CVE-2008-7220 and CVE-2007-2383 maybe GitHub can't detect prototypejs's vulnerabilities

References

NVD-CWE-noinfohttp://github.com/sstephenson/prototype/blob/master/CHANGELOGhttp://osvdb.org/46312https://bugzilla.redhat.com/show_bug.cgi?id=523277http://www.openwall.com/lists/oss-security/2009/11/07/2https://www.redhat.com/archives/fedora-package-announce/2009-November/msg00838.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-November/msg00789.htmlhttp://secunia.com/advisories/37479https://bugzilla.redhat.com/show_bug.cgi?id=533137http://secunia.com/advisories/37677http://www.debian.org/security/2009/dsa-1952https://seclists.org/bugtraq/2019/May/18http://packetstormsecurity.com/files/152787/dotCMS-5.1.1-Vulnerable-Dependencies.htmlhttp://seclists.org/fulldisclosure/2019/May/13http://seclists.org/fulldisclosure/2019/May/11http://seclists.org/fulldisclosure/2019/May/10https://lists.apache.org/thread.html/eff7280055fc717ea8129cd28a9dd57b8446d00b36260c1caee10b87%40%3Cnotifications.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/7ba863c5a4a0f1230cba2d11cf4de3a2eda3a42e8023d4990f564327%40%3Cdev.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/6d1b9a75a004dab42c81e8aa149d90e6fd26ce8cd6d71295e565e366%40%3Cissues.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/2ad48cd9d47edd0e677082eb869115809473a117e1e30b52fb511590%40%3Cissues.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/769fcc5f331b61c4d7ce16b807678e9a1799628d0146322e14aa24ed%40%3Cdev.zookeeper.apache.org%3Ehttps://nvd.nist.govhttps://bugs.debian.org/cgi-bin/bugreport.cgi?bug=555217