CVE-2008-2644
Published Jun 10, 2008
Last updated 6 years ago
Overview
- Description
- Multiple cross-site scripting (XSS) vulnerabilities in SMEWeb 1.4b and 1.4f allow remote attackers to inject arbitrary web script or HTML via the (1) data parameter to catalog.php, the (2) keyword parameter to search.php, the (3) page parameter to bb.php, and the (4) new_s parameter to order.php.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-79
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:smeweb:smeweb:1.4b:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A00053B6-CA20-4CC2-855B-734CFDE42007" }, { "criteria": "cpe:2.3:a:smeweb:smeweb:1.4f:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "41F0D730-35D3-4581-8CB1-CDDD0B36A2B9" } ], "operator": "OR" } ] } ]