Vulnerability Name: | CVE-2008-4571 (CCN-39350) | ||||||||
Assigned: | 2007-12-03 | ||||||||
Published: | 2007-12-03 | ||||||||
Updated: | 2008-11-15 | ||||||||
Summary: | Cross-site scripting (XSS) vulnerability in the LiveSearch module in Plone before 3.0.4 allows remote attackers to inject arbitrary web script or HTML via the Description field for search results, as demonstrated using the onerror Javascript even in an IMG tag. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-79 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2008-4571 Source: CCN Type: Plone Web site Ticket #7439: Possible XSS into LiveSearch module Source: CONFIRM Type: Exploit, Vendor Advisory http://dev.plone.org/plone/ticket/7439 Source: OSVDB Type: UNKNOWN 40660 Source: CONFIRM Type: Patch http://plone.org/products/plone/releases/3.0.4 Source: CCN Type: SA28293 Plone LiveSearch Module News Item Script Insertion Source: SECUNIA Type: Vendor Advisory 28293 Source: CCN Type: OSVDB ID: 40660 LiveSearch Module for Plone News Item Description Field XSS Source: BID Type: Patch 27098 Source: CCN Type: BID-27098 Plone 'LiveSearch' Module HTML Injection Vulnerability Source: XF Type: UNKNOWN plone-livesearch-xss(39350) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |