CVE-2008-1168

Publication date 5 March 2008

Last updated 24 July 2024


Ubuntu priority

Cross-site scripting (XSS) vulnerability in Squid Analysis Report Generator (Sarg) 2.2.3.1 allows remote attackers to inject arbitrary web script or HTML via the User-Agent header, which is not properly handled when displaying the Squid proxy log. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
sarg 9.10 karmic
Fixed 2.2.5-1
9.04 jaunty
Fixed 2.2.5-1
8.10 intrepid
Fixed 2.2.5-1
8.04 LTS hardy
Fixed 2.2.5-1
7.10 gutsy Ignored end of life, was needed
7.04 feisty Ignored end of life, was needed
6.10 edgy Ignored end of life, was needed
6.06 LTS dapper Ignored end of life