CVE-2008-7220
published 2009-09-13CVE-2008-7220: Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before 1.6.0.2 allows attackers to make "cross-site ajax requests" via unknown…
PriorityP337high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
13.36%
95.9th percentile
Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before 1.6.0.2 allows attackers to make "cross-site ajax requests" via unknown vectors.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | asterisk | < asterisk 1:1.6.2.0~rc3-1 (bullseye) | asterisk 1:1.6.2.0~rc3-1 (bullseye) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | exaile | < asterisk 1:1.6.2.0~rc3-1 (bullseye) | asterisk 1:1.6.2.0~rc3-1 (bullseye) |
| debian | jscropperui | < asterisk 1:1.6.2.0~rc3-1 (bullseye) | asterisk 1:1.6.2.0~rc3-1 (bullseye) |
| debian | libaws | < asterisk 1:1.6.2.0~rc3-1 (bullseye) | asterisk 1:1.6.2.0~rc3-1 (bullseye) |
| debian | libhtml-prototype-perl | < asterisk 1:1.6.2.0~rc3-1 (bullseye) | asterisk 1:1.6.2.0~rc3-1 (bullseye) |
| debian | otrs2 | < asterisk 1:1.6.2.0~rc3-1 (bullseye) | asterisk 1:1.6.2.0~rc3-1 (bullseye) |
| debian | passenger | < asterisk 1:1.6.2.0~rc3-1 (bullseye) | asterisk 1:1.6.2.0~rc3-1 (bullseye) |
| debian | prototypejs | < asterisk 1:1.6.2.0~rc3-1 (bullseye) | asterisk 1:1.6.2.0~rc3-1 (bullseye) |
| debian | scriptaculous | < asterisk 1:1.6.2.0~rc3-1 (bullseye) | asterisk 1:1.6.2.0~rc3-1 (bullseye) |
| debian | symfony | < asterisk 1:1.6.2.0~rc3-1 (bullseye) | asterisk 1:1.6.2.0~rc3-1 (bullseye) |
| debian | wordpress | < asterisk 1:1.6.2.0~rc3-1 (bullseye) | asterisk 1:1.6.2.0~rc3-1 (bullseye) |
| debian | zabbix | < asterisk 1:1.6.2.0~rc3-1 (bullseye) | asterisk 1:1.6.2.0~rc3-1 (bullseye) |
| prototypejs | prototype | < 1.6.0.2 | 1.6.0.2 |
| symfony | symfony | >= 0 < 1.0.21-1.1 | 1.0.21-1.1 |
| symfony | symfony | >= 0 < 1.0.21-1.1 | 1.0.21-1.1 |
| symfony | symfony | >= 0 < 1.0.21-1.1 | 1.0.21-1.1 |
| symfony | symfony | >= 0 < 1.0.21-1.1 | 1.0.21-1.1 |
| wordpress | wordpress | >= 0 < 2.5.0-2 | 2.5.0-2 |
| wordpress | wordpress | >= 0 < 2.5.0-2 | 2.5.0-2 |
| wordpress | wordpress | >= 0 < 2.5.0-2 | 2.5.0-2 |
| wordpress | wordpress | >= 0 < 2.5.0-2 | 2.5.0-2 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mgmj-3x8r-9rwj: Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before 1
ghsa_unreviewed·2022-05-13
CVE-2008-7220 [HIGH] GHSA-mgmj-3x8r-9rwj: Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before 1
Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before 1.6.0.2 allows attackers to make "cross-site ajax requests" via unknown vectors.
OSV
CVE-2008-7220: Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before 1
osv·2009-09-13·CVSS 7.5
CVE-2008-7220 [HIGH] CVE-2008-7220: Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before 1
Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before 1.6.0.2 allows attackers to make "cross-site ajax requests" via unknown vectors.
Red Hat
FrameWork: XSS Ajax requests (AST-2009-009)
vendor_redhat·2008-01-23·CVSS 7.5
CVE-2008-7220 [HIGH] CWE-79 FrameWork: XSS Ajax requests (AST-2009-009)
FrameWork: XSS Ajax requests (AST-2009-009)
Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before 1.6.0.2 allows attackers to make "cross-site ajax requests" via unknown vectors.
Debian
CVE-2008-7220: asterisk - Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before...
vendor_debian·2008·CVSS 7.5
CVE-2008-7220 [HIGH] CVE-2008-7220: asterisk - Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before...
Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before 1.6.0.2 allows attackers to make "cross-site ajax requests" via unknown vectors.
Scope: local
bullseye: resolved (fixed in 1:1.6.2.0~rc3-1)
sid: resolved (fixed in 1:1.6.2.0~rc3-1)
No detection rules found.
No public exploits indexed.
http://github.com/sstephenson/prototype/blob/master/CHANGELOGhttp://osvdb.org/46312http://packetstormsecurity.com/files/152787/dotCMS-5.1.1-Vulnerable-Dependencies.htmlhttp://seclists.org/fulldisclosure/2019/May/10http://seclists.org/fulldisclosure/2019/May/11http://seclists.org/fulldisclosure/2019/May/13http://secunia.com/advisories/37479http://secunia.com/advisories/37677http://www.debian.org/security/2009/dsa-1952http://www.openwall.com/lists/oss-security/2009/11/07/2https://bugzilla.redhat.com/show_bug.cgi?id=523277https://bugzilla.redhat.com/show_bug.cgi?id=533137https://lists.apache.org/thread.html/2ad48cd9d47edd0e677082eb869115809473a117e1e30b52fb511590%40%3Cissues.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/6d1b9a75a004dab42c81e8aa149d90e6fd26ce8cd6d71295e565e366%40%3Cissues.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/769fcc5f331b61c4d7ce16b807678e9a1799628d0146322e14aa24ed%40%3Cdev.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/7ba863c5a4a0f1230cba2d11cf4de3a2eda3a42e8023d4990f564327%40%3Cdev.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/eff7280055fc717ea8129cd28a9dd57b8446d00b36260c1caee10b87%40%3Cnotifications.zookeeper.apache.org%3Ehttps://seclists.org/bugtraq/2019/May/18https://www.redhat.com/archives/fedora-package-announce/2009-November/msg00789.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-November/msg00838.htmlhttp://github.com/sstephenson/prototype/blob/master/CHANGELOGhttp://osvdb.org/46312http://packetstormsecurity.com/files/152787/dotCMS-5.1.1-Vulnerable-Dependencies.htmlhttp://seclists.org/fulldisclosure/2019/May/10http://seclists.org/fulldisclosure/2019/May/11http://seclists.org/fulldisclosure/2019/May/13http://secunia.com/advisories/37479http://secunia.com/advisories/37677http://www.debian.org/security/2009/dsa-1952http://www.openwall.com/lists/oss-security/2009/11/07/2https://bugzilla.redhat.com/show_bug.cgi?id=523277https://bugzilla.redhat.com/show_bug.cgi?id=533137https://lists.apache.org/thread.html/2ad48cd9d47edd0e677082eb869115809473a117e1e30b52fb511590%40%3Cissues.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/6d1b9a75a004dab42c81e8aa149d90e6fd26ce8cd6d71295e565e366%40%3Cissues.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/769fcc5f331b61c4d7ce16b807678e9a1799628d0146322e14aa24ed%40%3Cdev.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/7ba863c5a4a0f1230cba2d11cf4de3a2eda3a42e8023d4990f564327%40%3Cdev.zookeeper.apache.org%3Ehttps://lists.apache.org/thread.html/eff7280055fc717ea8129cd28a9dd57b8446d00b36260c1caee10b87%40%3Cnotifications.zookeeper.apache.org%3Ehttps://seclists.org/bugtraq/2019/May/18https://www.redhat.com/archives/fedora-package-announce/2009-November/msg00789.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-November/msg00838.html
2009-09-13
Published