First published: Mon Jul 07 2008(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in the Send-A-Card (sr_sendcard) extension 2.2.2 and earlier for TYPO3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Typo3 Send A Card | =2.2 | |
Typo3 Send A Card | <=2.2.2 | |
Typo3 Send A Card | =2.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3028 is classified with a medium severity level due to its potential for cross-site scripting attacks.
To fix CVE-2008-3028, upgrade the Send-A-Card extension to version 2.2.3 or later.
CVE-2008-3028 affects the Send-A-Card extension versions 2.2.2 and earlier for TYPO3.
CVE-2008-3028 exposes users to cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts.
While specific exploits for CVE-2008-3028 are not documented, the nature of XSS vulnerabilities means they can often be exploited easily by attackers.