CVE-2015-1908
published 2015-04-27CVE-2015-1908: Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0…
PriorityP421medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.80%
76.2th percentile
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF16, and 8.5.0 through CF05, as used in Web Content Manager and other products, allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| ibm | websphere_portal | — | — |
| openbsd | openssh | >= 0 < 1:6.6p1-2ubuntu2.7 | 1:6.6p1-2ubuntu2.7 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qx5f-v3wq-8636: Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6
ghsa_unreviewed·2022-05-17
CVE-2015-1908 [MEDIUM] CWE-79 GHSA-qx5f-v3wq-8636: Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF16, and 8.5.0 through CF05, as used in Web Content Manager and other products, allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
OSV
openssh vulnerabilities
osv·2016-05-09·CVSS 7.8
CVE-2015-8325 openssh vulnerabilities
openssh vulnerabilities
Shayan Sadigh discovered that OpenSSH incorrectly handled environment files
when the UseLogin feature is enabled. A local attacker could use this issue
to gain privileges. (CVE-2015-8325)
Ben Hawkes discovered that OpenSSH incorrectly handled certain network
traffic. A remote attacker could possibly use this issue to cause OpenSSH
to crash, resulting in a denial of service. This issue only applied to
Ubuntu 15.10. (CVE-2016-1907)
Thomas Hoger discovered that OpenSSH incorrectly handled untrusted X11
forwarding when the SECURITY extension is disabled. A connection configured
as being untrusted could get switched to trusted in certain scenarios,
contrary to expectations. (CVE-2016-1908)
It was discovered that OpenSSH incorrectly handled certain X11 forwarding
data
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www-01.ibm.com/support/docview.wss?uid=swg1PI37661http://www-01.ibm.com/support/docview.wss?uid=swg21701566http://www.securityfocus.com/bid/74218http://www.securitytracker.com/id/1032189http://www-01.ibm.com/support/docview.wss?uid=swg1PI37661http://www-01.ibm.com/support/docview.wss?uid=swg21701566http://www.securityfocus.com/bid/74218http://www.securitytracker.com/id/1032189
2015-04-27
Published