Логотип exploitDog
bind:CVE-2008-1846
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2008-1846

Количество 2

Количество 2

nvd логотип

CVE-2008-1846

почти 18 лет назад

The default configuration of SAP NetWeaver before 7.0 SP15 does not enable the "Always Use Secure HTML Editor" (aka Editor Security or Secure Editing) parameter, which allows remote attackers to conduct cross-site scripting (XSS) attacks by entering feedback for a file.

CVSS2: 4.3
EPSS: Низкий
github логотип

GHSA-v2h7-hrfg-524r

почти 4 года назад

The default configuration of SAP NetWeaver before 7.0 SP15 does not enable the "Always Use Secure HTML Editor" (aka Editor Security or Secure Editing) parameter, which allows remote attackers to conduct cross-site scripting (XSS) attacks by entering feedback for a file.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2008-1846

The default configuration of SAP NetWeaver before 7.0 SP15 does not enable the "Always Use Secure HTML Editor" (aka Editor Security or Secure Editing) parameter, which allows remote attackers to conduct cross-site scripting (XSS) attacks by entering feedback for a file.

CVSS2: 4.3
1%
Низкий
почти 18 лет назад
github логотип
GHSA-v2h7-hrfg-524r

The default configuration of SAP NetWeaver before 7.0 SP15 does not enable the "Always Use Secure HTML Editor" (aka Editor Security or Secure Editing) parameter, which allows remote attackers to conduct cross-site scripting (XSS) attacks by entering feedback for a file.

1%
Низкий
почти 4 года назад

Уязвимостей на страницу