CVE-2008-3678
Published Aug 14, 2008
Last updated 7 years ago
Overview
- Description
- Cross-site scripting (XSS) vulnerability in admin/search_links.php in Freeway before 1.4.2.197 allows remote attackers to inject arbitrary web script or HTML via the URL.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-79
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:damian_hickey:freeway:1.0.60:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5425AFF2-8FC0-4C75-B7F1-BB19A40FBECA" }, { "criteria": "cpe:2.3:a:damian_hickey:freeway:1.1.0.76:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0F47BA19-3F04-425E-B944-C9436B990E8C" }, { "criteria": "cpe:2.3:a:damian_hickey:freeway:1.1.1.80:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CA346E49-B32F-4A91-BD54-D41D74A5DA68" }, { "criteria": "cpe:2.3:a:damian_hickey:freeway:1.2.0.113:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "70912B52-AF51-45C4-B6FD-8451EF825E24" }, { "criteria": "cpe:2.3:a:damian_hickey:freeway:1.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "097CE970-3980-4FB3-9846-7F3DC2316076" }, { "criteria": "cpe:2.3:a:damian_hickey:freeway:1.3.1.147:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "147F7E94-F7C7-4623-A130-D8AEEB36EB27" }, { "criteria": "cpe:2.3:a:damian_hickey:freeway:1.3.2.154:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C42C1462-1A9C-4EC7-BD3D-D6673FBBDC49" }, { "criteria": "cpe:2.3:a:damian_hickey:freeway:1.4.1.170:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "10712633-9115-485C-809A-EC299285A900" }, { "criteria": "cpe:2.3:a:damian_hickey:freeway:1.4.1.171:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A9D0C309-5C62-405C-8F39-92E5BC2B9F65" } ], "operator": "OR" } ] } ]