CVE-2008-2861
Multiple cross-site scripting (XSS) vulnerabilities in eLineStudio Site Composer (ESC) 2.6 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) topic and (2) button parameters to ansFAQ.asp and the (3) id and (4)…
Does this matter?
Lower severity and a low EPSS score (1.72%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in eLineStudio Site Composer (ESC) 2.6 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) topic and (2) button parameters to ansFAQ.asp and the (3) id and (4) txtEmail parameters to login.asp.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.72% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- elinestudio/site composer
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/30762Vendor Advisory
- http://securityreason.com/securityalert/3957
- http://www.securityfocus.com/archive/1/493473/100/0/threaded
- http://www.securityfocus.com/bid/29812Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43191
- https://www.exploit-db.com/exploits/5859
- http://secunia.com/advisories/30762Vendor Advisory
- http://securityreason.com/securityalert/3957
- http://www.securityfocus.com/archive/1/493473/100/0/threaded
- http://www.securityfocus.com/bid/29812Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43191
- https://www.exploit-db.com/exploits/5859
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.