CVE-2008-4918
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 6.4%
from disclosure to weapon0 days
Published on NVDNov 4
1st PoCOct 30
exploitation probability
6.4%top 7% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Cross-site scripting (XSS) vulnerability in SonicWALL SonicOS Enhanced before 4.0.1.1, as used in SonicWALL Pro 2040 and TZ 180 and 190, allows remote attackers to inject arbitrary web script or HTML into arbitrary web sites via a URL to a site that is blocked based on content filtering, which is not properly handled in the CFS block page, aka "universal website hijacking."
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/32552⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://secunia.com/advisories/32498http://securityreason.com/securityalert/4556https://exchange.xforce.ibmcloud.com/vulnerabilities/46232http://www.gnucitizen.org/blog/new-technique-to-perform-universal-website-hijacking/http://www.securityfocus.com/archive/1/497948/100/0/threadedhttp://www.securityfocus.com/archive/1/497958/100/0/threadedhttp://www.securityfocus.com/archive/1/497968/100/0/threadedhttp://www.securityfocus.com/archive/1/497989/100/0/threadedhttp://www.securityfocus.com/archive/1/498043/100/0/threadedhttp://www.securityfocus.com/archive/1/498073/100/0/threadedhttp://www.securityfocus.com/bid/31998http://www.sonicwall.com/downloads/SonicOS_Enhanced_4.0.1.1_Release_Notes.pdf