4.3
CVSSv2

CVE-2008-1229

Published: 10/03/2008 Updated: 29/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Edit.jsp in JSPWiki 2.4.104 and 2.5.139 allows remote malicious users to inject arbitrary web script or HTML via the editor parameter, a different vector than CVE-2007-5120.b.

Vulnerable Product Search on Vulmon Subscribe to Product

jspwiki jspwiki 2.5.139_beta

jspwiki jspwiki 2.4.104

jspwiki jspwiki 2.5.139

Exploits

JSPWiki Multiple Vulnerabilities Vendor: Janne Jalkanen JSPWiki – wwwjspwikiorg Application Description: From JSPWiki website - “JSPWiki is a feature-rich and extensible WikiWiki engine built around a standart J2EE components (Java, servlets, JSP)” Tested versions: JSPWiki v24104 JSPWiki v25139 Earlier versions ...