VulnerabilityModified
CVE-2008-7043
Cross-site scripting (XSS) vulnerability in register.php in FreshScripts Fresh Email Script 1.0 through 1.11 allows remote attackers to inject arbitrary web script or HTML via the Email parameter.
MEDIUM 4.3EPSS 1.72%
Does this matter?
Lower severity and a low EPSS score (1.72%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in register.php in FreshScripts Fresh Email Script 1.0 through 1.11 allows remote attackers to inject arbitrary web script or HTML via the Email parameter. NOTE: this can be leveraged to modify cookies and conduct session fixation attacks.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.72% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- freshscripts/fresh email script
- Source
- cve@mitre.org
References
- http://osvdb.org/49849
- http://secunia.com/advisories/32642Vendor Advisory
- http://www.securityfocus.com/bid/32241Exploit
- http://www.vupen.com/english/advisories/2008/3096Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46529
- https://www.exploit-db.com/exploits/7080
- http://osvdb.org/49849
- http://secunia.com/advisories/32642Vendor Advisory
- http://www.securityfocus.com/bid/32241Exploit
- http://www.vupen.com/english/advisories/2008/3096Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46529
- https://www.exploit-db.com/exploits/7080
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.