First published: Thu Sep 11 2008(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in index.php in the Bluemoon PopnupBLOG module 3.20 and 3.30 for XOOPS allow remote attackers to inject arbitrary web script or HTML via the (1) param, (2) cat_id, and (3) view parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Bluemoon PopnupBLOG | =3.20 | |
Bluemoon PopnupBLOG | =3.30 | |
Xoops Xm Memberstats |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4053 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2008-4053, upgrade the Bluemoon PopnupBLOG module to version 3.31 or later which addresses these vulnerabilities.
CVE-2008-4053 can be exploited through the param, cat_id, and view parameters in the index.php file.
Users of Bluemoon PopnupBLOG versions 3.20 and 3.30 for XOOPS are affected by CVE-2008-4053.
CVE-2008-4053 utilizes cross-site scripting (XSS) as the attack vector, allowing attackers to inject arbitrary web scripts.