4.3
CVSSv2

CVE-2008-4571

Published: 15/10/2008 Updated: 15/11/2008
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the LiveSearch module in Plone prior to 3.0.4 allows remote malicious users to inject arbitrary web script or HTML via the Description field for search results, as demonstrated using the onerror Javascript even in an IMG tag.

Vulnerable Product Search on Vulmon Subscribe to Product

plone plone 2.5.1

plone plone 2.5_beta1

plone plone 2.0.5

plone plone 3.0

plone plone 2.5

plone plone 2.1.2

plone plone 2.5.4

plone plone 2.5.1_rc

plone plone 3.0.1

plone plone 3.0.2

plone plone