CVE-2008-4053: XSS
Multiple cross-site scripting (XSS) vulnerabilities in index.php in the Bluemoon PopnupBLOG module 3.20 and 3.30 for XOOPS allow remote attackers to inject arbitrary web script or HTML via the (1) param, (2) catid, and (3) view parameters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4053?
CVE-2008-4053 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2008-4053?
To fix CVE-2008-4053, upgrade the Bluemoon PopnupBLOG module to version 3.31 or later which addresses these vulnerabilities.
What types of parameters are exploited in CVE-2008-4053?
CVE-2008-4053 can be exploited through the param, cat_id, and view parameters in the index.php file.
Who is affected by CVE-2008-4053?
Users of Bluemoon PopnupBLOG versions 3.20 and 3.30 for XOOPS are affected by CVE-2008-4053.
What attack vector does CVE-2008-4053 utilize?
CVE-2008-4053 utilizes cross-site scripting (XSS) as the attack vector, allowing attackers to inject arbitrary web scripts.