Unrated severityNVD Advisory· Published Feb 22, 2008· Updated Apr 23, 2026
CVE-2008-0919
CVE-2008-0919
Description
Cross-site scripting (XSS) vulnerability in session/login.php in Open Source Security Information Management (OSSIM) 0.9.9 rc5 and earlier allows remote attackers to inject arbitrary web script or HTML via the dest parameter.
Affected products
25cpe:2.3:a:open_source_security_information_management:os-sim:0.1alpha:*:*:*:*:*:*:*+ 24 more
- cpe:2.3:a:open_source_security_information_management:os-sim:0.1alpha:*:*:*:*:*:*:*
- cpe:2.3:a:open_source_security_information_management:os-sim:0.2alpha:*:*:*:*:*:*:*
- cpe:2.3:a:open_source_security_information_management:os-sim:0.3.1alpha:*:*:*:*:*:*:*
- cpe:2.3:a:open_source_security_information_management:os-sim:0.3alpha:*:*:*:*:*:*:*
- cpe:2.3:a:open_source_security_information_management:os-sim:0.5.1:*:*:*:*:*:*:*
- cpe:2.3:a:open_source_security_information_management:os-sim:0.5.2:*:*:*:*:*:*:*
- cpe:2.3:a:open_source_security_information_management:os-sim:0.6:*:*:*:*:*:*:*
- cpe:2.3:a:open_source_security_information_management:os-sim:0.6.2:*:*:*:*:*:*:*
- cpe:2.3:a:open_source_security_information_management:os-sim:0.6.3:*:*:*:*:*:*:*
- cpe:2.3:a:open_source_security_information_management:os-sim:0.7:*:*:*:*:*:*:*
- cpe:2.3:a:open_source_security_information_management:os-sim:0.7.1:*:*:*:*:*:*:*
- cpe:2.3:a:open_source_security_information_management:os-sim:0.8:*:*:*:*:*:*:*
- cpe:2.3:a:open_source_security_information_management:os-sim:0.9:*:*:*:*:*:*:*
- cpe:2.3:a:open_source_security_information_management:os-sim:0.9.1:*:*:*:*:*:*:*
- cpe:2.3:a:open_source_security_information_management:os-sim:0.9.2:*:*:*:*:*:*:*
- cpe:2.3:a:open_source_security_information_management:os-sim:0.9.3:*:*:*:*:*:*:*
- cpe:2.3:a:open_source_security_information_management:os-sim:0.9.4:*:*:*:*:*:*:*
- cpe:2.3:a:open_source_security_information_management:os-sim:0.9.5:*:*:*:*:*:*:*
- cpe:2.3:a:open_source_security_information_management:os-sim:0.9.6:*:*:*:*:*:*:*
- cpe:2.3:a:open_source_security_information_management:os-sim:0.9.7:*:*:*:*:*:*:*
- cpe:2.3:a:open_source_security_information_management:os-sim:0.9.8:*:*:*:*:*:*:*
- cpe:2.3:a:open_source_security_information_management:os-sim:0.9.9_rc1:*:*:*:*:*:*:*
- cpe:2.3:a:open_source_security_information_management:os-sim:0.9.9_rc2:*:*:*:*:*:*:*
- cpe:2.3:a:open_source_security_information_management:os-sim:0.9.9_rc3:*:*:*:*:*:*:*
- cpe:2.3:a:open_source_security_information_management:os-sim:0.9.9_rc4:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- www.securityfocus.com/bid/27929nvdExploitPatch
- osvdb.org/42006nvd
- secunia.com/advisories/29046nvd
- securityreason.com/securityalert/3689nvd
- www.securityfocus.com/archive/1/488450/100/0/threadednvd
- www.securityfocus.com/archive/1/488617/100/0/threadednvd
- www.securityfocus.com/archive/1/488697/100/0/threadednvd
- www.exploit-db.com/exploits/5171nvd
News mentions
0No linked articles in our index yet.