Lucene search

K
cveMitreCVE-2008-1536
HistoryMar 28, 2008 - 6:44 p.m.

CVE-2008-1536

2008-03-2818:44:00
CWE-79
mitre
web.nvd.nist.gov
23
cve-2008-1536
xss
index.php
tim grissett
remote attackers
web script
html
amessage parameter
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.7

Confidence

High

EPSS

0.002

Percentile

61.3%

Cross-site scripting (XSS) vulnerability in index.php in Pictures Pro (aka Tim Grissett) Photo Cart 4.1 allows remote attackers to inject arbitrary web script or HTML via the amessage parameter. NOTE: some of these details are obtained from third party information.

Affected configurations

Nvd
Node
picturespropicturespro_photo_cartMatch4.1
VendorProductVersionCPE
picturespropicturespro_photo_cart4.1cpe:2.3:a:picturespro:picturespro_photo_cart:4.1:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.7

Confidence

High

EPSS

0.002

Percentile

61.3%

Related for CVE-2008-1536