CVE-2008-3782
Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in ACG-PTP 1.0.6 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) Category name field under Advertisement Packages, the (2) Reason field…
Does this matter?
Lower severity and a low EPSS score (0.84%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in ACG-PTP 1.0.6 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) Category name field under Advertisement Packages, the (2) Reason field under Credit/Debit Users, and the (3) FAQ question and (4) FAQ answer fields under Add New FAQ Entry.
- CVSS 2.0
- 3.5 LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
- EPSS
- 0.84% probability · 56th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- discountedscripts/acg ptp
- Source
- cve@mitre.org
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2008-August/064038.html
- http://secunia.com/advisories/31591Vendor Advisory
- http://www.securityfocus.com/bid/30793
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44603
- http://lists.grok.org.uk/pipermail/full-disclosure/2008-August/064038.html
- http://secunia.com/advisories/31591Vendor Advisory
- http://www.securityfocus.com/bid/30793
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44603
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.