4.3
CVSSv2

CVE-2008-4888

Published: 04/11/2008 Updated: 29/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in error.php in NetRisk 2.0 and previous versions allows remote malicious users to inject arbitrary web script or HTML via the error parameter to index.php. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

netrisk netrisk 1.9.7

netrisk netrisk

Exploits

# ----------------------------------------------------------------- # NetRisk <= 20 (XSS/SQL Injection) Remote Vulnerabilities # ----------------------------------------------------------------- # Discovered By StAkeR aka athos # Download On downloadssourceforgenet/netrisk # Works Regardless Of phpini Settings! # --------------------- ...