CVE-2008-0180: XSS
Published Feb 4, 2008
·Updated
Cross-site scripting (XSS) vulnerability in themes/unstyled/templates/init.vm in Liferay Portal 4.3.6 allows remote authenticated users to inject arbitrary web script or HTML via the Greeting field in a User Profile.
Affected Software
12 affected components
Liferay Liferay Enterprise Portal
Liferay Liferay Enterprise Portal=1.0
Liferay Liferay Enterprise Portal=2.0
Liferay Liferay Enterprise Portal=2.1.0
Liferay Liferay Enterprise Portal=2.1.1
Liferay Liferay Enterprise Portal=2.2.0
Liferay Liferay Enterprise Portal=3.6.1
Liferay Liferay Enterprise Portal=4.1
Liferay Liferay Enterprise Portal=4.1.1
Liferay Liferay Enterprise Portal=4.1.3
Liferay Liferay Enterprise Portal=4.3.1
Liferay Liferay Enterprise Portal=4.3.6
Event History
Feb 4, 2008
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-0180?
CVE-2008-0180 is considered a medium severity vulnerability due to the potential for cross-site scripting attacks.
2
Who is affected by CVE-2008-0180?
CVE-2008-0180 affects users of Liferay Portal versions 4.3.6 and earlier.
3
How do I fix CVE-2008-0180?
To fix CVE-2008-0180, it is recommended to upgrade to a patched version of Liferay Portal that addresses the XSS vulnerability.
4
What type of vulnerability is CVE-2008-0180?
CVE-2008-0180 is a cross-site scripting (XSS) vulnerability.
5
What can an attacker do exploit CVE-2008-0180?
An attacker can exploit CVE-2008-0180 to inject arbitrary web scripts or HTML into user profiles.