CVE-2008-0925

Cross-site scripting (XSS) vulnerability in the iMonitor interface in Novell eDirectory 8.7.3.x before 8.7.3 sp10, and 8.8.x before 8.8.2 ftf2, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters that are used within "error messages of the HTTP stack."
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 75%
VendorProductVersion
novelledirectory
8.7.3.9
novelledirectory
8.7.3.9
novelledirectory
8.7.3.9
novelledirectory
8.7.3.9
novelledirectory
8.8
novelledirectory
8.8
novelledirectory
8.8
novelledirectory
8.8
novelledirectory
8.8.1
novelledirectory
8.8.1
novelledirectory
8.8.1
novelledirectory
8.8.1
novelledirectory
8.8.2
novelledirectory
8.8.2
novelledirectory
8.8.2
novelledirectory
8.8.2
𝑥
= Vulnerable software versions