CVE-2008-6885: XSS
Published Jul 31, 2009
·Updated
Cross-site scripting (XSS) vulnerability in pmlite.php in XOOPS 2.3.1 and 2.3.2a allows remote attackers to inject arbitrary web script or HTML via a STYLE attribute in a URL BBcode tag in a private message.
Affected Software
2 affected components
Xoops Xoops=2.3.2a
Xoops Xoops=2.3.1
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Jul 31, 2009
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-6885?
CVE-2008-6885 is classified as a medium severity cross-site scripting vulnerability.
2
How do I fix CVE-2008-6885?
To fix CVE-2008-6885, it is recommended to upgrade to a patched version of XOOPS that addresses this vulnerability.
3
Which versions of XOOPS are affected by CVE-2008-6885?
CVE-2008-6885 affects XOOPS versions 2.3.1 and 2.3.2a.
4
What type of attack is possible with CVE-2008-6885?
CVE-2008-6885 allows remote attackers to perform cross-site scripting attacks via injected scripts in private messages.
5
Can CVE-2008-6885 be exploited without authentication?
Yes, CVE-2008-6885 can be exploited by unauthenticated users if they can send private messages.