CVE-2008-7092
Summary
| CVE | CVE-2008-7092 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-08-26 14:24:17 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in Unica Affinium Campaign 7.2.1.0.55 allow remote attackers to inject arbitrary web script or HTML via a Javascript event in the (1) url, (2) PageName, and (3) title parameters in a CustomBookMarkLink action to Campaign/Campaign; (4) a Javascript event in the displayIcon parameter to Campaign/updateOfferTemplateSubmit.do (aka the templates web page); (5) crafted input to Campaign/CampaignListener (aka the listener server), which is not properly handled when displaying the status log; and (6) id parameter to Campaign/campaignDetails.do, (7) id parameter to Campaign/offerDetails.do, (8) function parameter to Campaign/Campaign, (9) sessionID parameter to Campaign/runAllFlowchart.do, (10) id parameter in an edit action to Campaign/updateOfferTemplatePage.do, (11) Frame parameter in a LoadFrame action to Campaign/Campaign, (12) affiniumUserName parameter to manager/jsp/test.jsp, (13) affiniumUserName parameter to Campaign/main.do, and possibly other vectors. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Unica | Affinium Campaign | 7.2.1.0.55 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.osvdb.org/47521 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | Exploit |
| www.osvdb.org/47523 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | Exploit |
| www.osvdb.org/47528 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| Affinium Campaign Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Portcullis - Affinium Campaign's status log web page is vulnerable to a second order Jav | af854a3a-2127-422b-91ae-364da2661108 | www.portcullis.co.uk | Exploit |
| www.osvdb.org/47525 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | Exploit |
| www.osvdb.org/47524 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | Exploit |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Portcullis - Affinium Campaign's parameters are vulnerable to reflected JavaScript injec | af854a3a-2127-422b-91ae-364da2661108 | www.portcullis.co.uk | Exploit |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Portcullis - Affinium Campaign's templates web page is vulnerable to a JavaScript inject | af854a3a-2127-422b-91ae-364da2661108 | www.portcullis.co.uk | Exploit |
| www.osvdb.org/47530 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | Exploit |
| www.osvdb.org/47526 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| www.osvdb.org/47522 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | Exploit |
| Unica Affinium Campaign Multiple Remote Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| www.osvdb.org/47520 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | Exploit |
| Portcullis - Affinium Campaign's bookmarks web page is vulnerable to a JavaScript inject | af854a3a-2127-422b-91ae-364da2661108 | www.portcullis.co.uk | Exploit |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.