Lucene search

K
cveMitreCVE-2008-3679
HistoryAug 14, 2008 - 7:41 p.m.

CVE-2008-3679

2008-08-1419:41:00
CWE-79
mitre
web.nvd.nist.gov
30
cve-2008-3679
cross-site scripting
xss
web security
idevspot phplinkexchange
vulnerability

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.7

Confidence

High

EPSS

0.002

Percentile

57.2%

Multiple cross-site scripting (XSS) vulnerabilities in index.php in IDevSpot PhpLinkExchange 1.01 allow remote attackers to inject arbitrary web script or HTML via the catid parameter in a (1) user_add, (2) recip, (3) tellafriend, or (4) contact action, or (5) in a request without an action; or (6) the id parameter in a tellafriend action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Affected configurations

Nvd
Node
idevspotphplinkexchangeMatch1.01
VendorProductVersionCPE
idevspotphplinkexchange1.01cpe:2.3:a:idevspot:phplinkexchange:1.01:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.7

Confidence

High

EPSS

0.002

Percentile

57.2%

Related for CVE-2008-3679