CVE-2008-1953: XSS
Published Apr 25, 2008
·Updated
Cross-site scripting (XSS) vulnerability in the Sitedesigner before 1.1.5 search template in Magnolia Enterprise Edition allows remote attackers to inject arbitrary web script or HTML via the query parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Affected Software
1 affected component
Magnolia Site Designer<=1.0.13
Remediation
Patch Available
Event History
Apr 25, 2008
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-1953?
The severity of CVE-2008-1953 is rated as medium with a score of 4.3.
2
How do I fix CVE-2008-1953?
To fix CVE-2008-1953, apply the available patch for the Sitedesigner prior to version 1.1.5.
3
What type of vulnerability is CVE-2008-1953?
CVE-2008-1953 is a Cross-Site Scripting (XSS) vulnerability.
4
What software is affected by CVE-2008-1953?
CVE-2008-1953 affects the Magnolia Site Designer.
5
Can CVE-2008-1953 allow attackers to execute scripts on a site?
Yes, CVE-2008-1953 allows remote attackers to inject arbitrary web scripts or HTML via the query parameter.