CVE-2008-3316
Cross-site scripting (XSS) vulnerability in the search feature in the Forum plugin before 2.7.1 for Geeklog allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably related to (1) public_html/index.php, (2)…
Does this matter?
Lower severity and a low EPSS score (1.22%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in the search feature in the Forum plugin before 2.7.1 for Geeklog allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably related to (1) public_html/index.php, (2) config.php, and (3) functions.inc.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.22% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- portalparts/forum plugin
- Source
- cve@mitre.org
References
- http://jvn.jp/en/jp/JVN60419863/index.html
- http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000045.html
- http://secunia.com/advisories/31188Vendor Advisory
- http://www.geeklog.net/article.php/20080719093147449
- http://www.securityfocus.com/bid/30355
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43971
- http://jvn.jp/en/jp/JVN60419863/index.html
- http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000045.html
- http://secunia.com/advisories/31188Vendor Advisory
- http://www.geeklog.net/article.php/20080719093147449
- http://www.securityfocus.com/bid/30355
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43971
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.