CVE-2008-1896: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Carbon Communities 2.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Redirect parameter to login.asp and the (2) OrderBy parameter to membersend.asp.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1896?
CVE-2008-1896 has a moderate severity rating due to its impact on user data and the potential for exploitation.
How do I fix CVE-2008-1896?
To fix CVE-2008-1896, you should update Carbon Communities to version 2.5 or later, which addresses the XSS vulnerabilities.
What are the affected versions for CVE-2008-1896?
CVE-2008-1896 affects Carbon Communities versions 2.4 and earlier, including versions 1.0, 1.1, 2.1, 2.2, and 2.3.
What types of attacks are possible with CVE-2008-1896?
CVE-2008-1896 allows attackers to perform cross-site scripting (XSS) attacks by injecting arbitrary web scripts via vulnerable parameters.
Who is impacted by CVE-2008-1896?
Users and organizations utilizing Carbon Communities versions 2.4 and earlier are impacted by CVE-2008-1896.