NA
CVSSv3

CVE-2008-5211

CVSSv4: NA | CVSSv3: NA | CVSSv2: 2.6 | VMScore: 360 | EPSS: 0.03788 | KEV: Not Included
Published: 24/11/2008 Updated: 21/11/2024

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in search.php in Sphider 1.3.4, when the search suggestion feature is enabled, allows remote malicious users to inject arbitrary web script or HTML via the query parameter, a different vector than CVE-2006-2506.

Vulnerable Product Search on Vulmon Subscribe to Product

sphider sphider 1.3.4

Exploits

source: wwwsecurityfocuscom/bid/29074/info Sphider is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site This may help the atta ...