4.3
CVSSv2

CVE-2008-5225

Published: 25/11/2008 Updated: 11/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 445
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in Xerox DocuShare 6 and previous versions allow remote malicious users to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) SearchResults/ and (2) Services/ in dsdn/dsweb/, and (3) the default URI under unspecified docushare/dsweb/ServicesLib/Group-#/ directories.

Vulnerable Product Search on Vulmon Subscribe to Product

xerox docushare 5

xerox docushare 5.00.00.2

xerox docushare 6.00.00.1

xerox docushare 6.0.1

xerox docushare 4

xerox docushare

xerox docushare 6.0

Exploits

source: wwwsecurityfocuscom/bid/29430/info Xerox DocuShare is prone to multiple cross-site scripting vulnerabilities An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site This may help the attacker steal cookie-based authentication credentia ...
source: wwwsecurityfocuscom/bid/29430/info Xerox DocuShare is prone to multiple cross-site scripting vulnerabilities An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site This may help the attacker steal cookie-based authentication credentials a ...
source: wwwsecurityfocuscom/bid/29430/info Xerox DocuShare is prone to multiple cross-site scripting vulnerabilities An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site This may help the attacker steal cookie-based authentication credentials ...