4.3
CVSSv2

CVE-2008-5918

Published: 21/01/2009 Updated: 29/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the getParameterisedSelfUrl function in index.php in WebSVN 2.0 and previous versions allows remote malicious users to inject arbitrary web script or HTML via the PATH_INFO.

Vulnerable Product Search on Vulmon Subscribe to Product

tigris websvn 1.38

tigris websvn 1.37

tigris websvn 1.04

tigris websvn 1.03

tigris websvn

tigris websvn 1.60

tigris websvn 1.61

tigris websvn 1.34

tigris websvn 1.33

tigris websvn 1.02

tigris websvn 1.01

tigris websvn 1.62

tigris websvn 1.51

tigris websvn 1.32

tigris websvn 1.31a

tigris websvn 1.00

tigris websvn 1.40

tigris websvn 1.39

tigris websvn 1.20

tigris websvn 1.10

Exploits

WebSVN <= 20 Multiple Vulnerabilities October 20, 2008 Vendor : Tim Armes URL : websvntigrisorg Version : WebSVN <= 20 Risk : Multiple Vulnerabilities Description: WebSVN is an online SVN repository viewer The description taken from the project website reads "WebSVN offers a view onto your subversion repositories that's b ...