CVE-2008-6340: XSS
Published Feb 27, 2009
·Updated
Cross-site scripting (XSS) vulnerability in the Vox populi (mvvoxpopuli) extension 0.3.0 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
8 affected components
Mathieu Vidal Mv Vox Populi<=0.3.0
Mathieu Vidal Mv Vox Populi=0.1.0
Mathieu Vidal Mv Vox Populi=0.2.0
Typo3 TYPO3
All of the following
Any of the following
Mathieu Vidal Mv Vox Populi<=0.3.0
Mathieu Vidal Mv Vox Populi=0.1.0
Mathieu Vidal Mv Vox Populi=0.2.0
Typo3 TYPO3
Remediation
Patch Available
Event History
Feb 27, 2009
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
05:30 PM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·05:30 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-6340?
CVE-2008-6340 is classified as a high severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2008-6340?
To fix CVE-2008-6340, upgrade the Vox populi extension to a version later than 0.3.0.
3
What software is affected by CVE-2008-6340?
CVE-2008-6340 affects the Vox populi extension versions 0.3.0 and earlier for TYPO3.
4
What kind of attacks can be executed because of CVE-2008-6340?
CVE-2008-6340 allows remote attackers to inject arbitrary web scripts or HTML into the affected TYPO3 installations.
5
Is there a known exploit for CVE-2008-6340?
Yes, CVE-2008-6340 has been documented and can be exploited by attackers to perform cross-site scripting attacks.