Bug Source: XMB 1.9.9 and older
Symptoms: Unexpected output, Javascript compromise (XSS)
Security Impact: High
ID: CVE-2007-0519
Fixed By: XMB 1.9.10 and later are not affected.
Discussion:
In 2007, a CVE was assigned to a public XSS exploit against the XMB U2U feature. XMB staff evaluated this information in 2008, and determined version
1.9.8 contained an incomplete solution, but the CVE was still valid for one or more defects. U2U functions were revised and released with version
1.9.10 to implement better I/O filtering. These changes were also available in a service pack for version 1.9.8.
Recommendations: