CVE-2008-2025
published 2009-04-09CVE-2008-2025: Cross-site scripting (XSS) vulnerability in Apache Struts before 1.2.9-162.31.1 on SUSE Linux Enterprise (SLE) 11, before 1.2.9-108.2 on SUSE openSUSE 10.3…
PriorityP424medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
7.91%
94.1th percentile
Cross-site scripting (XSS) vulnerability in Apache Struts before 1.2.9-162.31.1 on SUSE Linux Enterprise (SLE) 11, before 1.2.9-108.2 on SUSE openSUSE 10.3, before 1.2.9-198.2 on SUSE openSUSE 11.0, and before 1.2.9-162.163.2 on SUSE openSUSE 11.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "insufficient quoting of parameters."
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| apache | struts | — | — |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1809 | — | — |
| msrc | windows_10_version_21h2 | — | — |
| msrc | windows_10_version_22h2 | — | — |
| msrc | windows_11_version_22h2 | — | — |
| msrc | windows_11_version_23h2 | — | — |
| msrc | windows_11_version_24h2 | — | — |
| msrc | windows_11_version_25h2 | — | — |
| msrc | windows_server_2008 | — | — |
| msrc | windows_server_2008_for_32-bit_systems_service_pack_2 | — | — |
| msrc | windows_server_2008_for_x64-based_systems_service_pack_2 | — | — |
| msrc | windows_server_2008_r2 | — | — |
| msrc | windows_server_2008_r2_for_x64-based_systems_service_pack_1 | — | — |
| msrc | windows_server_2012 | — | — |
| msrc | windows_server_2012_r2 | — | — |
| msrc | windows_server_2016 | — | — |
| msrc | windows_server_2019 | — | — |
| msrc | windows_server_2022 | — | — |
| msrc | windows_server_2022_23h2_edition | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_msrc8.8HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Struts Cross-site Scripting vulnerability
osv·2022-05-01
CVE-2008-2025 [MEDIUM] Apache Struts Cross-site Scripting vulnerability
Apache Struts Cross-site Scripting vulnerability
Cross-site scripting (XSS) vulnerability in Apache Struts before 1.2.9-162.31.1 on SUSE Linux Enterprise (SLE) 11, before 1.2.9-108.2 on SUSE openSUSE 10.3, before 1.2.9-198.2 on SUSE openSUSE 11.0, and before 1.2.9-162.163.2 on SUSE openSUSE 11.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "insufficient quoting of parameters."
GHSA
Apache Struts Cross-site Scripting vulnerability
ghsa·2022-05-01
CVE-2008-2025 [MEDIUM] CWE-79 Apache Struts Cross-site Scripting vulnerability
Apache Struts Cross-site Scripting vulnerability
Cross-site scripting (XSS) vulnerability in Apache Struts before 1.2.9-162.31.1 on SUSE Linux Enterprise (SLE) 11, before 1.2.9-108.2 on SUSE openSUSE 10.3, before 1.2.9-198.2 on SUSE openSUSE 11.0, and before 1.2.9-162.163.2 on SUSE openSUSE 11.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "insufficient quoting of parameters."
Red Hat
kernel: spufs: fix a leak in spufs_create_context()
vendor_redhat·2025-04-16·CVSS 5.5
CVE-2025-22071 [MEDIUM] kernel: spufs: fix a leak in spufs_create_context()
kernel: spufs: fix a leak in spufs_create_context()
In the Linux kernel, the following vulnerability has been resolved:
spufs: fix a leak in spufs_create_context()
Leak fixes back in 2008 missed one case - if we are trying to set affinity
and spufs_mkdir() fails, we need to drop the reference to neighbor.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affected
Package: kernel (Red Hat Enterprise Linux 9) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 9) - Not aff
Microsoft
MapUrlToZone Security Feature Bypass Vulnerability
vendor_msrc·2025-01-14·CVSS 4.3
CVE-2025-21332 [MEDIUM] CWE-41 MapUrlToZone Security Feature Bypass Vulnerability
MapUrlToZone Security Feature Bypass Vulnerability
FAQ: The Security Updates table indicates that this vulnerability affects all supported versions of Microsoft Windows. Why are IE Cumulative updates listed for Windows Server 2008, Windows Server 2008 R2, Windows Server 2012, and Windows Server 2012 R2?
While Microsoft has announced retirement of the Internet Explorer 11 application on certain platforms and the Microsoft Edge Legacy application is deprecated, the underlying MSHTML, EdgeHTML, and scripting platforms are still supported. The MSHTML platform is used by Internet Explorer mode in Microsoft Edge as well as other applications through WebBrowser control. The EdgeHTML platform is used by WebView and some UWP applications. The scripting platforms are used by MSHTML and EdgeHTML but
Red Hat
struts: XSS vulnerability
vendor_redhat·2009-04-06·CVSS 4.3
CVE-2008-2025 [MEDIUM] CWE-79 struts: XSS vulnerability
struts: XSS vulnerability
Cross-site scripting (XSS) vulnerability in Apache Struts before 1.2.9-162.31.1 on SUSE Linux Enterprise (SLE) 11, before 1.2.9-108.2 on SUSE openSUSE 10.3, before 1.2.9-198.2 on SUSE openSUSE 11.0, and before 1.2.9-162.163.2 on SUSE openSUSE 11.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "insufficient quoting of parameters."
Statement: This is not a security flaw in Struts. Struts has never guaranteed to perform filtering of the untrusted user inputs used as html tag attributes names or values. If user inputs need to be used as part of the tag attributes, the JSP page needs to perform filtering explicitly. For further details, see: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2008-2025
Citrix
Citrix Security Bulletin CTX116930
vendor_citrix·CVSS 10.0
CVE-2008-2528 [CRITICAL] Citrix Security Bulletin CTX116930
Citrix Security Bulletin CTX116930
CVE References: CVE-2008-2528, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX116310
vendor_citrix·CVSS 6.8
CVE-2008-4676 [MEDIUM] Citrix Security Bulletin CTX116310
Citrix Security Bulletin CTX116310
CVE References: CVE-2008-4676, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX116227
vendor_citrix·CVSS 1.9
CVE-2008-6561 [LOW] Citrix Security Bulletin CTX116227
Citrix Security Bulletin CTX116227
CVE References: CVE-2008-6561, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX114487
vendor_citrix·CVSS 10.0
CVE-2008-0356 [CRITICAL] Citrix Security Bulletin CTX114487
Citrix Security Bulletin CTX114487
CVE References: CVE-2008-0356, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX117751
vendor_citrix·CVSS 7.2
CVE-2008-5121 [HIGH] Citrix Security Bulletin CTX117751
Citrix Security Bulletin CTX117751
CVE References: CVE-2008-5121, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-22071 kernel: spufs: fix a leak in spufs_create_context()
bugzilla·2025-04-16·CVSS 5.5
CVE-2025-22071 [MEDIUM] CVE-2025-22071 kernel: spufs: fix a leak in spufs_create_context()
CVE-2025-22071 kernel: spufs: fix a leak in spufs_create_context()
In the Linux kernel, the following vulnerability has been resolved:
spufs: fix a leak in spufs_create_context()
Leak fixes back in 2008 missed one case - if we are trying to set affinity
and spufs_mkdir() fails, we need to drop the reference to neighbor.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025041610-CVE-2025-22071-ca32@gregkh/T
Bugzilla
CVE-2008-2025 struts: XSS vulnerability
bugzilla·2009-04-09·CVSS 4.3
CVE-2008-2025 [MEDIUM] CVE-2008-2025 struts: XSS vulnerability
CVE-2008-2025 struts: XSS vulnerability
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-2025 to
the following vulnerability:
Name: CVE-2008-2025
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2025
Assigned: 20080430
Reference: MISC: https://bugzilla.novell.com/show_bug.cgi?id=385273
Reference: MISC: https://launchpad.net/bugs/cve/2008-2025
Reference: CONFIRM: http://download.opensuse.org/update/10.3-test/repodata/patch-struts-5872.xml
Reference: CONFIRM: http://support.novell.com/security/cve/CVE-2008-2025.html
Reference: SUSE:SUSE-SR:2009:008
Reference: URL: http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00003.html
Cross-site scripting (XSS) vulnerability in Apache Struts before
1.2.9-162.31.1 on SUSE Linux Enterprise (SLE) 11, before
http://download.opensuse.org/update/10.3-test/repodata/patch-struts-5872.xmlhttp://lists.opensuse.org/opensuse-security-announce/2009-04/msg00003.htmlhttp://osvdb.org/53380http://secunia.com/advisories/34567http://secunia.com/advisories/34642http://support.novell.com/security/cve/CVE-2008-2025.htmlhttps://bugzilla.novell.com/show_bug.cgi?id=385273https://launchpad.net/bugs/cve/2008-2025http://download.opensuse.org/update/10.3-test/repodata/patch-struts-5872.xmlhttp://lists.opensuse.org/opensuse-security-announce/2009-04/msg00003.htmlhttp://osvdb.org/53380http://secunia.com/advisories/34567http://secunia.com/advisories/34642http://support.novell.com/security/cve/CVE-2008-2025.htmlhttps://bugzilla.novell.com/show_bug.cgi?id=385273https://launchpad.net/bugs/cve/2008-2025
2009-04-09
Published