CVE-2008-3316 Information

Description

Cross-site scripting (XSS) vulnerability in the search feature in the Forum plugin before 2.7.1 for Geeklog allows remote attackers to inject arbitrary web script or HTML via unspecified vectors probably related to (1) public_html/index.php (2) config.php and (3) functions.inc.

Reference

http://jvn.jp/en/jp/JVN60419863/index.html http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000045.html http://secunia.com/advisories/31188 http://www.geeklog.net/article.php/20080719093147449 http://www.securityfocus.com/bid/30355 https://exchange.xforce.ibmcloud.com/vulnerabilities/43971

Share on: