Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2008-1168
HistoryMar 05, 2008 - 11:44 p.m.

CVE-2008-1168

2008-03-0523:44:00
Debian Security Bug Tracker
security-tracker.debian.org
6

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.003 Low

EPSS

Percentile

70.9%

Cross-site scripting (XSS) vulnerability in Squid Analysis Report Generator (Sarg) 2.2.3.1 allows remote attackers to inject arbitrary web script or HTML via the User-Agent header, which is not properly handled when displaying the Squid proxy log. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

OSVersionArchitecturePackageVersionFilename
Debian12allsarg< 2.2.5-1sarg_2.2.5-1_all.deb
Debian999allsarg< 2.2.5-1sarg_2.2.5-1_all.deb
Debian13allsarg< 2.2.5-1sarg_2.2.5-1_all.deb

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

0.003 Low

EPSS

Percentile

70.9%