← Back

CVE-2008-5185

nvd nist
Published: Nov 21, 2008Modified: Apr 23, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

The highlighting functionality in geshi.php in GeSHi before 1.0.8 allows remote attackers to cause a denial of service (infinite loop) via an XML sequence containing an opening delimiter without a closing delimiter, as demonstrated using "<".

Affected (31)

Products: Geshi: Geshi
1 product
Geshi
Configuration A
31 vulnerable
Vulnerable SoftwareAffected Versions
Geshi
Up to 1.0.7.22
Version 1.0.0
Version 1.0.1
Version 1.0.2
Version 1.0.2_beta_1
Version 1.0.3
Version 1.0.4
Version 1.0.5
Version 1.0.6
Version 1.0.7.10
Version 1.0.7.11
Version 1.0.7.12
Version 1.0.7.13
Version 1.0.7.14
Version 1.0.7.15
Version 1.0.7.16
Version 1.0.7.17
Version 1.0.7.18
Version 1.0.7.19
Version 1.0.7.1
Version 1.0.7.20
Version 1.0.7.21
Version 1.0.7.2
Version 1.0.7.3
Version 1.0.7.4
Version 1.0.7.5
Version 1.0.7.6
Version 1.0.7.7
Version 1.0.7.8
Version 1.0.7.9
Version 1.0.7

Related CWEs

Timeline

No history available yet.