INFORMATION
Name | : | CVE-2008-5172 | First Publication | : | 2008-11-19 |
Severity | : | Medium | Last Modification | : | 2008-11-19 |
SCORING CVSS v2
Cvss Base Score | : | 4.3 | Attack Range | : | Network |
Cvss Impact Score | : | 2.9 | Attack Complexity | : | Medium |
Cvss Expoit Score | : | 8.6 | Authentification | : | None Required |
Calculate full CVSS 2.0 Vectors scores | |||||
DETAIL
Multiple cross-site scripting (XSS) vulnerabilities in Yazd Forum Software 3.x allow remote attackers to inject arbitrary web script or HTML via the (1) q parameter to (a) search.jsp, and the (2) msg parameter to (b) error.jsp and (c) userAccount.jsp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.




(Medium)



