CVE-2008-0540
Multiple cross-site scripting (XSS) vulnerabilities in trixbox 2.4.2.0 allow remote attackers to inject arbitrary web script or HTML via the query string to index.php in (1) user/ or (2) maint/.
- Affected products
- Trixbox
- Trixbox
- = 2.4.2.0
- CVSS 2.0
- 4.3 MEDIUM
- EPSS
- 1.3% (70th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2008-02-01
CVE-2008-0540 at NVD
2 known exploits for CVE-2008-0540
Proof-of-concept code and exploit modules indexed by Sploitus