Lucene search

K
cveMitreCVE-2008-2758
HistoryJun 18, 2008 - 10:41 p.m.

CVE-2008-2758

2008-06-1822:41:00
CWE-79
mitre
web.nvd.nist.gov
24
cve
2008
2758
xss
vulnerabilities
xigla
absolute news manager
remote authenticated
admins
web script
html
admin
search
publishers
anmviewer
editarticlex

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

AI Score

5.5

Confidence

High

EPSS

0.001

Percentile

50.7%

Multiple cross-site scripting (XSS) vulnerabilities in Xigla Absolute News Manager XE 3.2 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) pblname and (2) text parameters to (a) admin/search.asp, (3) name parameter to (b) admin/publishers.asp, and other unspecified vectors to © anmviewer.asp and (d) editarticleX.asp in admin/. NOTE: some of these details are obtained from third party information.

Affected configurations

Nvd
Node
xiglaabsolute_news_manager_xeMatch3.2
VendorProductVersionCPE
xiglaabsolute_news_manager_xe3.2cpe:2.3:a:xigla:absolute_news_manager_xe:3.2:*:*:*:*:*:*:*

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

AI Score

5.5

Confidence

High

EPSS

0.001

Percentile

50.7%

Related for CVE-2008-2758