← Vulnerability feed

Vulnerability record · CVE-2008-6096 · published 9 February 2009

CVE-2008-6096: Juniper netscreen screenos cross-site scripting vulnerability

Juniper · Netscreen Screenos

Cross-site scripting (XSS) vulnerability in Juniper NetScreen ScreenOS before 5.4r10, 6.0r6, and 6.1r2 allows remote attackers to inject arbitrary web script or HTML via the user name parameter to the (1) web interface login page or the (2) telnet login page.

4.3 CVSS 2.0 Medium EPSS 1.0% · top 37.6% CWE-79 · Cross-site scripting
4.3CVSS 2.0 base score
1.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

Cross-site scripting (XSS) vulnerability in Juniper NetScreen ScreenOS before 5.4r10, 6.0r6, and 6.1r2 allows remote attackers to inject arbitrary web script or HTML via the user name parameter to the (1) web interface login page or the (2) telnet login page.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-6096 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

5.4CVE-2018-0059Juniper netscreen screenos cross-site scripting vulnerabilityA persistent cross-site scripting vulnerability in the graphical user interface of ScreenOS may allow a remote authenticated user to inject web scrip…EPSS 0.80%5.0CVE-2005-2640Neoteris instant virtual extranet vulnerabilityBehavioral discrepancy information leak in Juniper Netscreen VPN running ScreenOS 5.2.0 and earlier, when using IKE with pre-shared key authenticatio…EPSS 7.1%5.0CVE-2004-1446Juniper netscreen screenos vulnerabilityUnknown vulnerability in ScreenOS in Juniper Networks NetScreen firewall 3.x through 5.x allows remote attackers to cause a denial of service (device…EPSS 3.1%5.0CVE-2002-1547Juniper netscreen screenos vulnerabilityNetscreen running ScreenOS 4.0.0r6 and earlier allows remote attackers to cause a denial of service via a malformed SSH packet to the Secure Command …EPSS 3.5%5.0CVE-2002-2150Juniper netscreen screenos vulnerabilityFirewalls from multiple vendors empty state tables more slowly than they are filled, which allows remote attackers to flood state tables with packet …EPSS 2.0%5.0CVE-2002-0891Juniper netscreen screenos vulnerabilityThe web interface (WebUI) of NetScreen ScreenOS before 2.6.1r8, and certain 2.8.x and 3.0.x versions before 3.0.3r1, allows remote attackers to cause…EPSS 1.6%2.1CVE-2002-0234Juniper netscreen screenos vulnerabilityNetScreen ScreenOS before 2.6.1 does not support a maximum number of concurrent sessions for a system, which allows an attacker on the trusted networ…EPSS 0.35%2.1CVE-2001-0589Juniper netscreen screenos vulnerabilityNetScreen ScreenOS prior to 2.5r6 on the NetScreen-10 and Netscreen-100 can allow a local attacker to bypass the DMZ 'denial' policy via specific tra…EPSS 0.33%

Source: NIST National Vulnerability Database (record CVE-2008-6096), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.