Lucene search

K
cve[email protected]CVE-2008-2939
HistoryAug 06, 2008 - 6:41 p.m.

CVE-2008-2939

2008-08-0618:41:00
CWE-79
web.nvd.nist.gov
299
cve-2008-2939
cross-site scripting
xss
apache
mod_proxy_ftp
ftp
nvd

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.7 Medium

AI Score

Confidence

High

0.072 Low

EPSS

Percentile

94.0%

Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web script or HTML via a wildcard in the last directory component in the pathname in an FTP URI.

Affected configurations

NVD
Node
apachehttp_serverRangeโ‰ค2.0.63
OR
apachehttp_serverRange2.2.0โ€“2.2.9
Node
applemac_os_xRangeโ‰ค10.5.6
OR
canonicalubuntu_linuxMatch6.06lts
OR
canonicalubuntu_linuxMatch7.10
OR
canonicalubuntu_linuxMatch8.04lts
OR
opensuseopensuseMatch10.2
OR
opensuseopensuseMatch10.3
OR
opensuseopensuseMatch11.0

References

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.7 Medium

AI Score

Confidence

High

0.072 Low

EPSS

Percentile

94.0%