CVE-2008-3937
Multiple cross-site scripting (XSS) vulnerabilities in Open Media Collectors Database (OpenDb) 1.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) user_id parameter in an edit action to user_admin.php, the (2) title parameter…
Does this matter?
Lower severity and a low EPSS score (1.36%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Open Media Collectors Database (OpenDb) 1.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) user_id parameter in an edit action to user_admin.php, the (2) title parameter to listings.php, and the (3) redirect_url parameter to user_profile.php.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.36% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- opendb/opendb
- Source
- cve@mitre.org
References
- http://packetstorm.linuxsecurity.com/0808-exploits/omcd-xssxsrf.txtExploit
- http://secunia.com/advisories/31719Vendor Advisory
- http://www.securityfocus.com/bid/30989
- http://packetstorm.linuxsecurity.com/0808-exploits/omcd-xssxsrf.txtExploit
- http://secunia.com/advisories/31719Vendor Advisory
- http://www.securityfocus.com/bid/30989
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.