Lucene search

K
nvd[email protected]NVD:CVE-2008-1502
HistoryMar 25, 2008 - 7:44 p.m.

CVE-2008-1502

2008-03-2519:44:00
CWE-79
web.nvd.nist.gov
6

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.4

Confidence

High

EPSS

0.007

Percentile

80.3%

The _bad_protocol_once function in phpgwapi/inc/class.kses.inc.php in KSES, as used in eGroupWare before 1.4.003, Moodle before 1.8.5, and other products, allows remote attackers to bypass HTML filtering and conduct cross-site scripting (XSS) attacks via a string containing crafted URL protocols.

Affected configurations

Nvd
Node
egroupwareegroupwareRange1.4.002
OR
egroupwareegroupwareMatch1.0
OR
egroupwareegroupwareMatch1.0.1
OR
egroupwareegroupwareMatch1.0.3
OR
egroupwareegroupwareMatch1.0.6
OR
egroupwareegroupwareMatch1.2.106-2
OR
egroupwareegroupwareMatch1.4.001
OR
moodlemoodleRange1.8.4
OR
moodlemoodleMatch1.1.1
OR
moodlemoodleMatch1.2.0
OR
moodlemoodleMatch1.2.1
OR
moodlemoodleMatch1.3.0
OR
moodlemoodleMatch1.3.1
OR
moodlemoodleMatch1.3.2
OR
moodlemoodleMatch1.3.3
OR
moodlemoodleMatch1.3.4
OR
moodlemoodleMatch1.4.1
OR
moodlemoodleMatch1.4.2
OR
moodlemoodleMatch1.4.3
OR
moodlemoodleMatch1.4.4
OR
moodlemoodleMatch1.4.5
OR
moodlemoodleMatch1.5
OR
moodlemoodleMatch1.5.0beta
OR
moodlemoodleMatch1.5.1
OR
moodlemoodleMatch1.5.2
OR
moodlemoodleMatch1.5.3
OR
moodlemoodleMatch1.6.0
OR
moodlemoodleMatch1.6.1
OR
moodlemoodleMatch1.6.2
OR
moodlemoodleMatch1.6.3
OR
moodlemoodleMatch1.6.4
OR
moodlemoodleMatch1.6.5
OR
moodlemoodleMatch1.6.6
OR
moodlemoodleMatch1.6.7
OR
moodlemoodleMatch1.7.1
OR
moodlemoodleMatch1.7.2
OR
moodlemoodleMatch1.7.3
OR
moodlemoodleMatch1.7.4
OR
moodlemoodleMatch1.7.5
OR
moodlemoodleMatch1.7.6
OR
moodlemoodleMatch1.8.1
OR
moodlemoodleMatch1.8.2
OR
moodlemoodleMatch1.8.3
VendorProductVersionCPE
egroupwareegroupware*cpe:2.3:a:egroupware:egroupware:*:*:*:*:*:*:*:*
egroupwareegroupware1.0cpe:2.3:a:egroupware:egroupware:1.0:*:*:*:*:*:*:*
egroupwareegroupware1.0.1cpe:2.3:a:egroupware:egroupware:1.0.1:*:*:*:*:*:*:*
egroupwareegroupware1.0.3cpe:2.3:a:egroupware:egroupware:1.0.3:*:*:*:*:*:*:*
egroupwareegroupware1.0.6cpe:2.3:a:egroupware:egroupware:1.0.6:*:*:*:*:*:*:*
egroupwareegroupware1.2.106-2cpe:2.3:a:egroupware:egroupware:1.2.106-2:*:*:*:*:*:*:*
egroupwareegroupware1.4.001cpe:2.3:a:egroupware:egroupware:1.4.001:*:*:*:*:*:*:*
moodlemoodle*cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
moodlemoodle1.1.1cpe:2.3:a:moodle:moodle:1.1.1:*:*:*:*:*:*:*
moodlemoodle1.2.0cpe:2.3:a:moodle:moodle:1.2.0:*:*:*:*:*:*:*
Rows per page:
1-10 of 431

References

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.4

Confidence

High

EPSS

0.007

Percentile

80.3%