ID

VAR-200801-0057


CVE

CVE-2008-0494


TITLE

Endian Firewall of vpnum/userslist.php Vulnerable to cross-site scripting

Trust: 0.8

sources: JVNDB: JVNDB-2008-002665

DESCRIPTION

Cross-site scripting (XSS) vulnerability in vpnum/userslist.php in Endian Firewall 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the psearch parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. Exploiting this vulnerability could allow an attacker to perform cross-site scripting attacks on unsuspecting users in the context of the affected website. As a result, the attacker may be able to steal cookie-based authentication credentials and to launch other attacks. Endian Firewall 2.1.2 is reported vulnerable; other versions may also be affected. NOTE: This BID is being retired because information from the vendor indicates that the device is not prone to this issue

Trust: 2.07

sources: NVD: CVE-2008-0494 // JVNDB: JVNDB-2008-002665 // BID: 27477 // VULHUB: VHN-30619 // VULMON: CVE-2008-0494

AFFECTED PRODUCTS

vendor:endianmodel:firewallscope:eqversion:2.1.2

Trust: 2.7

sources: BID: 27477 // JVNDB: JVNDB-2008-002665 // CNNVD: CNNVD-200801-442 // NVD: CVE-2008-0494

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2008-0494
value: MEDIUM

Trust: 1.0

NVD: CVE-2008-0494
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-200801-442
value: MEDIUM

Trust: 0.6

VULHUB: VHN-30619
value: MEDIUM

Trust: 0.1

VULMON: CVE-2008-0494
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2008-0494
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-30619
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-30619 // VULMON: CVE-2008-0494 // JVNDB: JVNDB-2008-002665 // CNNVD: CNNVD-200801-442 // NVD: CVE-2008-0494

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-30619 // JVNDB: JVNDB-2008-002665 // NVD: CVE-2008-0494

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200801-442

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-200801-442

CONFIGURATIONS

sources: JVNDB: JVNDB-2008-002665

PATCH

title:Top Pageurl:http://www.endian.com/

Trust: 0.8

sources: JVNDB: JVNDB-2008-002665

EXTERNAL IDS

db:NVDid:CVE-2008-0494

Trust: 2.9

db:BIDid:27477

Trust: 2.1

db:JVNDBid:JVNDB-2008-002665

Trust: 0.8

db:CNNVDid:CNNVD-200801-442

Trust: 0.6

db:VULHUBid:VHN-30619

Trust: 0.1

db:VULMONid:CVE-2008-0494

Trust: 0.1

sources: VULHUB: VHN-30619 // VULMON: CVE-2008-0494 // BID: 27477 // JVNDB: JVNDB-2008-002665 // CNNVD: CNNVD-200801-442 // NVD: CVE-2008-0494

REFERENCES

url:http://www.securityfocus.com/bid/27477

Trust: 1.9

url:http://downloads.securityfocus.com/vulnerabilities/exploits/27477.html

Trust: 1.8

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2008-0494

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2008-0494

Trust: 0.8

url:http://www.endian.com/en/products/firewall/appliances/

Trust: 0.3

url:https://cwe.mitre.org/data/definitions/79.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-30619 // VULMON: CVE-2008-0494 // BID: 27477 // JVNDB: JVNDB-2008-002665 // CNNVD: CNNVD-200801-442 // NVD: CVE-2008-0494

CREDITS

syniack

Trust: 0.6

sources: CNNVD: CNNVD-200801-442

SOURCES

db:VULHUBid:VHN-30619
db:VULMONid:CVE-2008-0494
db:BIDid:27477
db:JVNDBid:JVNDB-2008-002665
db:CNNVDid:CNNVD-200801-442
db:NVDid:CVE-2008-0494

LAST UPDATE DATE

2025-04-10T23:13:08.171000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-30619date:2008-09-05T00:00:00
db:VULMONid:CVE-2008-0494date:2008-09-05T00:00:00
db:BIDid:27477date:2015-05-12T19:49:00
db:JVNDBid:JVNDB-2008-002665date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200801-442date:2008-09-05T00:00:00
db:NVDid:CVE-2008-0494date:2025-04-09T00:30:58.490

SOURCES RELEASE DATE

db:VULHUBid:VHN-30619date:2008-01-30T00:00:00
db:VULMONid:CVE-2008-0494date:2008-01-30T00:00:00
db:BIDid:27477date:2008-01-28T00:00:00
db:JVNDBid:JVNDB-2008-002665date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200801-442date:2008-01-30T00:00:00
db:NVDid:CVE-2008-0494date:2008-01-30T22:00:00