{"api_version":"1","generated_at":"2026-07-23T06:56:04+00:00","cve":"CVE-2008-0717","urls":{"html":"https://cve.report/CVE-2008-0717","api":"https://cve.report/api/cve/CVE-2008-0717.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-0717","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-0717"},"summary":{"title":"CVE-2008-0717","description":"Cross-site scripting (XSS) vulnerability in Caching Proxy (CP) 5.1 through 6.1 in IBM WebSphere Edge Server, when CGI mapping rules are enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors that trigger injection into an error response.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-02-12 02:00:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/27665","name":"http://www.securityfocus.com/bid/27665","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM WebSphere Edge Server Caching Proxy Cross-Site Scripting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securitytracker.com/id?1019315","name":"http://www.securitytracker.com/id?1019315","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - IBM WebSphere Edge Server Input Validation Hole in CGI Mapping Error Page Permits Cross-Site Scripting Attacks","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2008/0446","name":"http://www.vupen.com/english/advisories/2008/0446","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/28785","name":"http://secunia.com/advisories/28785","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"IBM WebSphere Edge Server Caching Proxy Cross-Site Scripting - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-1.ibm.com/support/docview.wss?uid=swg21294776","name":"http://www-1.ibm.com/support/docview.wss?uid=swg21294776","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM notice: The page you requested cannot be displayed","mime":"text/html","httpstatus":"404","archivestatus":"410"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-0717","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-0717","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"717","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_edge_server","cpe6":"5.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"717","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_edge_server","cpe6":"5.1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"717","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_edge_server","cpe6":"6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"717","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_edge_server","cpe6":"6.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"717","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_edge_server","cpe6":"6.0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"717","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_edge_server","cpe6":"6.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T07:54:23.055Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ADV-2008-0446","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/0446"},{"name":"27665","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/27665"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www-1.ibm.com/support/docview.wss?uid=swg21294776"},{"name":"1019315","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1019315"},{"name":"28785","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/28785"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-02-07T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in Caching Proxy (CP) 5.1 through 6.1 in IBM WebSphere Edge Server, when CGI mapping rules are enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors that trigger injection into an error response."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2008-02-14T10:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"ADV-2008-0446","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/0446"},{"name":"27665","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/27665"},{"tags":["x_refsource_CONFIRM"],"url":"http://www-1.ibm.com/support/docview.wss?uid=swg21294776"},{"name":"1019315","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1019315"},{"name":"28785","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/28785"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-0717","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in Caching Proxy (CP) 5.1 through 6.1 in IBM WebSphere Edge Server, when CGI mapping rules are enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors that trigger injection into an error response."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2008-0446","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2008/0446"},{"name":"27665","refsource":"BID","url":"http://www.securityfocus.com/bid/27665"},{"name":"http://www-1.ibm.com/support/docview.wss?uid=swg21294776","refsource":"CONFIRM","url":"http://www-1.ibm.com/support/docview.wss?uid=swg21294776"},{"name":"1019315","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1019315"},{"name":"28785","refsource":"SECUNIA","url":"http://secunia.com/advisories/28785"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-0717","datePublished":"2008-02-12T01:00:00.000Z","dateReserved":"2008-02-11T00:00:00.000Z","dateUpdated":"2024-08-07T07:54:23.055Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-02-12 02:00:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_edge_server:5.1:*:*:*:*:*:*:*","matchCriteriaId":"08801EB3-65CB-4C51-9AD0-6C0D673EAEEF"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_edge_server:5.1.1:*:*:*:*:*:*:*","matchCriteriaId":"1AA9C622-E53C-4A4F-9E5D-3FC8FFF1BA01"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_edge_server:6.0:*:*:*:*:*:*:*","matchCriteriaId":"715D4F1E-D987-4F4A-BAD2-CEDA473A8D78"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_edge_server:6.0.1:*:*:*:*:*:*:*","matchCriteriaId":"59D58504-D784-4571-B1B9-2B1E9B27BCB3"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_edge_server:6.0.2:*:*:*:*:*:*:*","matchCriteriaId":"A88AE0E9-6DAC-4DF4-8064-9744252AFAE9"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_edge_server:6.1:*:*:*:*:*:*:*","matchCriteriaId":"6484BEC4-E15B-4C8D-A241-55FD5DE9E7DC"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"717","Ordinal":"1","Title":"CVE-2008-0717","CVE":"CVE-2008-0717","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"717","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in Caching Proxy (CP) 5.1 through 6.1 in IBM WebSphere Edge Server, when CGI mapping rules are enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors that trigger injection into an error response.","Type":"Description","Title":"CVE-2008-0717"},{"CveYear":"2008","CveId":"717","Ordinal":"2","NoteData":"2008-02-11","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"717","Ordinal":"3","NoteData":"2008-02-14","Type":"Other","Title":"Modified"}]}}}