CVE-2008-0925

EUVD-2008-0932
Cross-site scripting (XSS) vulnerability in the iMonitor interface in Novell eDirectory 8.7.3.x before 8.7.3 sp10, and 8.8.x before 8.8.2 ftf2, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters that are used within "error messages of the HTTP stack."
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 77%
Affected Products (NVD)
VendorProductVersion
novelledirectory
8.7.3.9
novelledirectory
8.7.3.9
novelledirectory
8.7.3.9
novelledirectory
8.7.3.9
novelledirectory
8.8
novelledirectory
8.8
novelledirectory
8.8
novelledirectory
8.8
novelledirectory
8.8.1
novelledirectory
8.8.1
novelledirectory
8.8.1
novelledirectory
8.8.1
novelledirectory
8.8.2
novelledirectory
8.8.2
novelledirectory
8.8.2
novelledirectory
8.8.2
𝑥
= Vulnerable software versions