First published: Tue Aug 18 2009(Updated: )
Cross-site scripting (XSS) vulnerability in index.php in devalcms 1.4a allows remote attackers to inject arbitrary web script or HTML via the currentpath parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Usualtool CMS | =1.4a |
http://sourceforge.net/projects/devalcms/files/devalcms/devalcms-1.4b/devalcms-1.4b.zip/download
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-6982 is categorized as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2008-6982, upgrade to DevalCMS version 1.4b or later, which addresses this vulnerability.
CVE-2008-6982 is a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts.
CVE-2008-6982 affects users of DevalCMS version 1.4a.
The vulnerability in CVE-2008-6982 is exploited via the 'currentpath' parameter in index.php.