First published: Fri Feb 01 2008(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in trixbox 2.4.2.0 allow remote attackers to inject arbitrary web script or HTML via the query string to index.php in (1) user/ or (2) maint/.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Trixbox | =2.4.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0540 is rated as a moderate severity vulnerability due to its potential risks of cross-site scripting attacks.
To fix CVE-2008-0540, upgrade to a newer version of Trixbox that addresses these XSS vulnerabilities.
CVE-2008-0540 allows attackers to perform cross-site scripting attacks by injecting arbitrary web scripts into the application.
CVE-2008-0540 specifically affects Trixbox version 2.4.2.0.
Yes, CVE-2008-0540 can be exploited remotely through specially crafted query strings.