Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-2011

Опубликовано: 30 апр. 2008
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

Cross-site scripting (XSS) vulnerability in the National Rail Enquiries Live Departure Boards gadget before 1.1 allows remote National Rail Enquiries servers or man-in-the-middle attackers to inject arbitrary web script or HTML, and execute arbitrary code, via a response body, as demonstrated by a SCRIPT element that references a vbscript: URI.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:national_rail_enquiries:national_rail_enquiries_live_departure_boards:*:*:*:*:*:*:*:*
Версия до 1.1 (включая)

EPSS

Процентиль: 67%
0.00549
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-79

Связанные уязвимости

github
почти 4 года назад

Cross-site scripting (XSS) vulnerability in the National Rail Enquiries Live Departure Boards gadget before 1.1 allows remote National Rail Enquiries servers or man-in-the-middle attackers to inject arbitrary web script or HTML, and execute arbitrary code, via a response body, as demonstrated by a SCRIPT element that references a vbscript: URI.

EPSS

Процентиль: 67%
0.00549
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-79