CVE-2008-7220Cross-site Scripting in Prototype

Severity
7.5HIGHNVD
EPSS
10.0%
top 6.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 13
Latest updateMay 13

Description

Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before 1.6.0.2 allows attackers to make "cross-site ajax requests" via unknown vectors.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages15 packages

debiandebian/prototypejs< asterisk 1:1.6.2.0~rc3-1 (bullseye)
NVDprototypejs/prototype< 1.6.0.2
debiandebian/libhtml-prototype-perl< asterisk 1:1.6.2.0~rc3-1 (bullseye)
debiandebian/otrs2< asterisk 1:1.6.2.0~rc3-1 (bullseye)
debiandebian/exaile< asterisk 1:1.6.2.0~rc3-1 (bullseye)

Also affects: Debian Linux 5.0, 6.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-mgmj-3x8r-9rwj: Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before 12022-05-13
OSV
CVE-2008-7220: Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before 12009-09-13

📋Vendor Advisories

2
Red Hat
FrameWork: XSS Ajax requests (AST-2009-009)2008-01-23
Debian
CVE-2008-7220: asterisk - Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before...2008

💬Community

1
Bugzilla
CVE-2008-7220 WordPress, MediaTomb, python-webhelpers, Asterisk, Plone -- embedded Prototype JavaScript FrameWork: XSS Ajax requests (AST-2009-009)2009-09-14