CVE-2008-0917
Cross-site scripting (XSS) vulnerability in Tor World Tor Search 1.1 and earlier, I-Navigator 4.0, Mobile Frontier 2.1 and earlier, Diary.cgi (aka Quotes of the Day) 1.5 and earlier, Tor News 1.21 and earlier, Simple BBS 1.3 and earlier, Interactive BBS…
Does this matter?
Lower severity and a low EPSS score (1.03%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in Tor World Tor Search 1.1 and earlier, I-Navigator 4.0, Mobile Frontier 2.1 and earlier, Diary.cgi (aka Quotes of the Day) 1.5 and earlier, Tor News 1.21 and earlier, Simple BBS 1.3 and earlier, Interactive BBS 1.3 and earlier, Tor Board 1.1 and earlier, Simple Vote 1.1 and earlier, and Com Vote 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.03% probability · 62th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- tor world/com vote · tor world/i-navigator · tor world/interactive bbs · tor world/mobile frontier · tor world/quotes of the day · tor world/simple bbs · tor world/simple vote · tor world/tor board · tor world/tor news · tor world/tor search
- Source
- cve@mitre.org
References
- http://download.torworld.com/bug/20080221.html
- http://jvn.jp/jp/JVN%2354593414/index.html
- http://secunia.com/advisories/29039Vendor Advisory
- http://www.securityfocus.com/bid/27919
- http://download.torworld.com/bug/20080221.html
- http://jvn.jp/jp/JVN%2354593414/index.html
- http://secunia.com/advisories/29039Vendor Advisory
- http://www.securityfocus.com/bid/27919
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.