CVE-2008-4435
Multiple cross-site scripting (XSS) vulnerabilities in the RMSOFT Downloads Plus (rmdp) module 1.5 and 1.7 for Xoops allow remote attackers to inject arbitrary web script or HTML via the (1) key parameter to search.php and the (2) id parameter to down.php.
- Affected products
- Rmsoft Downloads Plus, Xoops
- Rmsoft Downloads Plus Module
- = 1.5, 1.7
- Fix
- Available
- CVSS 2.0
- 4.3 MEDIUM
- EPSS
- 1.5% (71th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2008-10-03
CVE-2008-4435 at NVD
2 known exploits for CVE-2008-4435
Proof-of-concept code and exploit modules indexed by Sploitus