CVE-2008-5067: XSS
Published Nov 13, 2008
·Updated
Cross-site scripting (XSS) vulnerability in search.php in Kmita Catalogue 2.x allows remote attackers to inject arbitrary web script or HTML via the q parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Affected Software
1 affected component
Kkeim Kmita Catalogue=2.0
Event History
Nov 13, 2008
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-5067?
CVE-2008-5067 is classified as a high severity cross-site scripting vulnerability.
2
How do I fix CVE-2008-5067?
To fix CVE-2008-5067, validate and sanitize user input for the q parameter in search.php.
3
Who is affected by CVE-2008-5067?
Users of Kmita Catalogue version 2.0 are affected by CVE-2008-5067.
4
What type of vulnerability is CVE-2008-5067?
CVE-2008-5067 is a cross-site scripting (XSS) vulnerability.
5
What can attackers do with CVE-2008-5067?
Attackers can inject arbitrary web scripts or HTML into the application through the q parameter.