CVE-2008-2035: XSS
Cross-site scripting (XSS) vulnerability in the Bluemoon, Inc. (1) BackPack 0.91 and earlier, (2) BmSurvey 0.84 and earlier, (3) newbbfileup 1.83 and earlier, (4) Newsembed (newsfileup) 1.44 and earlier, and (5) PopnupBlog 3.19 and earlier modules for XOOPS 2.0.x, XOOPS Cube 2.1, and ImpressCMS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-2035?
CVE-2008-2035 has a moderate severity rating due to its potential to allow cross-site scripting attacks.
How do I fix CVE-2008-2035?
To fix CVE-2008-2035, update the affected Bluemoon and XOOPS modules to their latest versions.
Which versions are affected by CVE-2008-2035?
CVE-2008-2035 affects BackPack 0.91 and earlier, BmSurvey 0.84 and earlier, and other listed modules prior to specific versions.
What are the potential impacts of exploiting CVE-2008-2035?
Exploiting CVE-2008-2035 can lead to unauthorized script execution in a user's browser, potentially compromising user data.
Is CVE-2008-2035 still a risk for users of XOOPS and Bluemoon modules?
Yes, if users have not updated to fixed versions, CVE-2008-2035 remains a significant risk.