Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-7140

Опубликовано: 01 сент. 2009
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

Multiple cross-site scripting (XSS) vulnerabilities in @lex Guestbook 4.0.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) language_setup parameter to setup.php or (2) test parameter to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: a third party has been reported that the test parameter is not used in @lex Guestbook.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:alexguestbook:\@lex_guestbook:*:*:*:*:*:*:*:*
Версия до 4.0.5 (включая)
cpe:2.3:a:alexguestbook:\@lex_guestbook:3.12:*:*:*:*:*:*:*
cpe:2.3:a:alexguestbook:\@lex_guestbook:3.13:*:*:*:*:*:*:*
cpe:2.3:a:alexguestbook:\@lex_guestbook:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:alexguestbook:\@lex_guestbook:4.0.2:*:*:*:*:*:*:*
cpe:2.3:a:alexguestbook:\@lex_guestbook:4.0.4:*:*:*:*:*:*:*

EPSS

Процентиль: 38%
0.00164
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-79

Связанные уязвимости

github
больше 3 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in @lex Guestbook 4.0.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) language_setup parameter to setup.php or (2) test parameter to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: a third party has been reported that the test parameter is not used in @lex Guestbook.

EPSS

Процентиль: 38%
0.00164
Низкий

4.3 Medium

CVSS2

Дефекты

CWE-79