CVE-2008-7213
Cross-site scripting (XSS) vulnerability in mambots/editors/mostlyce/jscripts/tiny_mce/filemanager/connectors/php/connector.php in MOStlyCE before 2.4, as used in Mambo 4.6.3 and earlier, allows remote attackers to inject arbitrary web script or HTML…
Does this matter?
Lower severity and a low EPSS score (2.15%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in mambots/editors/mostlyce/jscripts/tiny_mce/filemanager/connectors/php/connector.php in MOStlyCE before 2.4, as used in Mambo 4.6.3 and earlier, allows remote attackers to inject arbitrary web script or HTML via the Command parameter.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 2.15% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- mambo-foundation/mambo · brilaps/mostlyce
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2008-02/0444.html
- http://forum.mambo-foundation.org/showthread.php?t=10158
- http://osvdb.org/42530
- http://secunia.com/advisories/28670Vendor Advisory
- http://www.bugreport.ir/index_33.htmExploit
- http://www.securityfocus.com/archive/1/487128/100/200/threaded
- http://www.securityfocus.com/bid/27470Exploit
- http://www.vupen.com/english/advisories/2008/0325Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39984
- http://archives.neohapsis.com/archives/bugtraq/2008-02/0444.html
- http://forum.mambo-foundation.org/showthread.php?t=10158
- http://osvdb.org/42530
- http://secunia.com/advisories/28670Vendor Advisory
- http://www.bugreport.ir/index_33.htmExploit
- http://www.securityfocus.com/archive/1/487128/100/200/threaded
- http://www.securityfocus.com/bid/27470Exploit
- http://www.vupen.com/english/advisories/2008/0325Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39984
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.