CVE-2008-1468
Summary
| CVE | CVE-2008-1468 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-03-24 21:44:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Cross-site scripting (XSS) vulnerability in namazu.cgi in Namazu before 2.0.18 allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded input, related to failure to set the charset, a different vector than CVE-2004-1318 and CVE-2001-1350. NOTE: some of these details are obtained from third party information. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Namazu | Namazu | 1.3.0.11 | All | All | All |
| Application | Namazu | Namazu | 2.0 | All | All | All |
| Application | Namazu | Namazu | 2.0.12 | All | All | All |
| Application | Namazu | Namazu | 2.0.13 | All | All | All |
| Application | Namazu | Namazu | 2.0.14 | All | All | All |
| Application | Namazu | Namazu | 2.0.15 | All | All | All |
| Application | Namazu | Namazu | 2.0.16 | All | All | All |
| Application | Namazu | Namazu | 2.0.2 | All | All | All |
| Application | Namazu | Namazu | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| JVN#00892830: Namazu におけるクロスサイトスクリプティングの脆弱性 | af854a3a-2127-422b-91ae-364da2661108 | jvn.jp | |
| SUSE Update for Multiple Packages - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| '[security bulletin] HPSBMA02525 SSRT100083 rev.1 - HP System Insight Manager Running on HP-UX, Linux' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Namazu 'namazu.cgi' Cross-Site Scripting Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| [security-announce] SUSE Security Summary Report SUSE-SR:2008:017 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| [SECURITY] Fedora 8 Update: namazu-2.0.18-1.fc8 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Fedora update for namazu - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| HPSBMA02492 SSRT100079 rev.1 - HP System Management Homepage (SMH) for Linux and Windows, Remote Cross Site Scripting (XSS), Denial of Service (DoS), Execution of Arbitrary Code, Unauthorized Access - c02029444 - HP Business Support Center | af854a3a-2127-422b-91ae-364da2661108 | h20000.www2.hp.com | |
| HP Systems Insight Manager Multiple Vulnerabilities - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Namazu namazu.cgi UTF-7 Cross-Site Scripting - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Namazu: Security Considerations | af854a3a-2127-422b-91ae-364da2661108 | www.namazu.org | |
| [SECURITY] Fedora 7 Update: namazu-2.0.18-1.fc7 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| JVN:JVN#00892830 | MITRE | jvn.jp | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.