CVE-2008-2035
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD
Description
Cross-site scripting (XSS) vulnerability in the Bluemoon, Inc. (1) BackPack 0.91 and earlier, (2) BmSurvey 0.84 and earlier, (3) newbb_fileup 1.83 and earlier, (4) News_embed (news_fileup) 1.44 and earlier, and (5) PopnupBlog 3.19 and earlier modules for XOOPS 2.0.x, XOOPS Cube 2.1, and ImpressCMS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected (7)
Products: Bluemoon: Backpack, Bmsurvey, Newbb Fileup, News Fileup, Popnupblog · Xoops: Xoops, Xoops Cube
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 0.91 | |
| Up to 0.84 | |
| Up to 1.83 | |
| Up to 1.44 | |
| Up to 3.19 | |
| Version 2.0 | |
| Version 2.1 |
References (10)
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.