| Vulnerability Name: | CVE-2008-1037 (CCN-40828) | ||||||||
| Assigned: | 2008-02-24 | ||||||||
| Published: | 2008-02-24 | ||||||||
| Updated: | 2018-10-11 | ||||||||
| Summary: | Cross-site scripting (XSS) vulnerability in the file listing function in the web management interface in Packeteer PacketShaper and PolicyCenter 8.2.2 allows remote attackers to inject arbitrary web script or HTML via the FILELIST parameter to an arbitrary component, which triggers injection into an Error Report page. | ||||||||
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
| CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 4.1 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:U/RC:UR)
4.1 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:U/RC:UR)
| ||||||||
| Vulnerability Type: | CWE-79 | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: CCN Type: BugTraq Mailing List, Wed Jul 20 2005 - 01:34:29 CDT Packeteer Products File Listing XSS Source: MITRE Type: CNA CVE-2008-1037 Source: CCN Type: SA29119 Packeteer PacketShaper "FILELIST" Cross-Site Scripting Source: SECUNIA Type: UNKNOWN 29119 Source: SREASON Type: UNKNOWN 3701 Source: CCN Type: SECTRACK ID: 1019501 Packeteer PacketShaper Input Validation Hole in 'FILELIST' Parameter Permits Cross-Site Scripting Attacks Source: CCN Type: OSVDB ID: 42392 Packeteer Multiple Products File Listing Function Error Report page FILELIST Parameter XSS Source: CCN Type: Packeteer Web site Packeteer: The Market Leader in WAN Optimization Source: BUGTRAQ Type: UNKNOWN 20080224 Packeteer Products File Listing XSS Source: BID Type: Exploit 27982 Source: CCN Type: BID-27982 Packeteer PacketShaper and PolicyCenter 'FILELIST' Parameter Cross-Site Scripting Vulnerability Source: SECTRACK Type: UNKNOWN 1019501 Source: XF Type: UNKNOWN packeteer-filelist-xss(40828) | ||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||