VulnerabilityModified
CVE-2008-2852
Cross-site scripting (XSS) vulnerability in CGIWrap before 4.1, when an Internet Explorer based browser is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to failure to set the charset in error…
MEDIUM 4.3EPSS 1.25%
Does this matter?
Lower severity and a low EPSS score (1.25%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in CGIWrap before 4.1, when an Internet Explorer based browser is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to failure to set the charset in error messages.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.25% probability · 68th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- nathan neulinger/cgiwrap
- Source
- cve@mitre.org
References
- http://cgiwrap.sourceforge.net/changes.html
- http://jvn.jp/en/jp/JVN45389864/index.htmlPatch
- http://secunia.com/advisories/30765Vendor Advisory
- http://sourceforge.net/project/shownotes.php?group_id=8209&release_id=607349Patch
- http://www.securityfocus.com/bid/29811
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43176
- http://cgiwrap.sourceforge.net/changes.html
- http://jvn.jp/en/jp/JVN45389864/index.htmlPatch
- http://secunia.com/advisories/30765Vendor Advisory
- http://sourceforge.net/project/shownotes.php?group_id=8209&release_id=607349Patch
- http://www.securityfocus.com/bid/29811
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43176
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.