CVE-2008-2163

Cross-site scripting (XSS) vulnerability in IBM Lotus Quickr 8.1 before Hotfix 5 for Windows and AIX, and before Hotfix 3 for i5/OS, allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to "WYSIWYG editors."
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:ibm:aix:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i5os:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_nt:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_quickr:8.1:*:*:*:*:*:*:*

History

21 Nov 2024, 00:46

Type Values Removed Values Added
References () http://secunia.com/advisories/30204 - Vendor Advisory () http://secunia.com/advisories/30204 - Vendor Advisory
References () http://www-01.ibm.com/support/docview.wss?uid=swg27013341 - () http://www-01.ibm.com/support/docview.wss?uid=swg27013341 -
References () http://www-1.ibm.com/support/docview.wss?uid=swg24018711 - Patch () http://www-1.ibm.com/support/docview.wss?uid=swg24018711 - Patch
References () http://www.securityfocus.com/bid/29175 - () http://www.securityfocus.com/bid/29175 -
References () http://www.vupen.com/english/advisories/2008/1502/references - () http://www.vupen.com/english/advisories/2008/1502/references -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/42360 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/42360 -

Information

Published : 2008-05-13 17:20

Updated : 2024-11-21 00:46


NVD link : CVE-2008-2163

Mitre link : CVE-2008-2163

CVE.ORG link : CVE-2008-2163


JSON object : View

Products Affected

ibm

  • lotus_quickr
  • aix
  • i5os

microsoft

  • windows_nt
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')