VulnerabilityModified
CVE-2008-1896
Multiple cross-site scripting (XSS) vulnerabilities in Carbon Communities 2.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Redirect parameter to login.asp and the (2) OrderBy parameter to member_send.asp.
MEDIUM 4.3EPSS 1.72%
Does this matter?
Lower severity and a low EPSS score (1.72%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Carbon Communities 2.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Redirect parameter to login.asp and the (2) OrderBy parameter to member_send.asp.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.72% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- carboncommunities/carbon communities
- Source
- cve@mitre.org
References
- http://bugreport.ir/index.php?/35Exploit
- http://secunia.com/advisories/29827Vendor Advisory
- http://www.securityfocus.com/archive/1/490923/100/0/threaded
- http://www.securityfocus.com/bid/28806Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41846
- https://www.exploit-db.com/exploits/5456
- http://bugreport.ir/index.php?/35Exploit
- http://secunia.com/advisories/29827Vendor Advisory
- http://www.securityfocus.com/archive/1/490923/100/0/threaded
- http://www.securityfocus.com/bid/28806Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41846
- https://www.exploit-db.com/exploits/5456
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.