CVE-2008-0769

Opentext Livelink Ecm - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in Livelink ECM 9.0.0 through 9.7.0 and possibly earlier does not set the charset, which allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded input.

Scores

EPSS 0.0033
EPSS Percentile 55.5%

Classification

CWE
CWE-79
Status draft

Affected Products (8)

opentext/livelink_ecm
opentext/livelink_ecm
opentext/livelink_ecm
opentext/livelink_ecm
opentext/livelink_ecm
opentext/livelink_ecm
opentext/livelink_ecm
opentext/livelink_ecm

Timeline

Published Feb 14, 2008
Tracked Since Feb 18, 2026