[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2008-5814Date: (C)2009-01-02   (M)2024-02-22


Cross-site scripting (XSS) vulnerability in PHP, possibly 5.2.7 and earlier, when display_errors is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: because of the lack of details, it is unclear whether this is related to CVE-2006-0208.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 2.6
Exploit Score: 4.9
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: HIGH
Authentication: NONE
Confidentiality: NONE
Integrity: PARTIAL
Availability: NONE
  
Reference:
SECUNIA-34830
SECUNIA-34933
SECUNIA-35003
SECUNIA-35007
SECUNIA-35108
ADV-2009-1338
DSA-1789
HPSBMA02426
HPSBMA02492
JVN#50327700
JVNDB-2008-000084
RHSA-2009:0350
USN-761-1
USN-761-2
oval:org.mitre.oval:def:10501
php-directives-xss(47496)

CPE    94
cpe:/a:php:php:5.0.0:rc3
cpe:/a:php:php:3.0
cpe:/a:php:php:5.0.0:rc2
cpe:/a:php:php:5.0.0:rc1
...
CWE    1
CWE-79
OVAL    11
oval:org.secpod.oval:def:202156
oval:org.secpod.oval:def:102424
oval:org.secpod.oval:def:700321
oval:org.secpod.oval:def:500602
...

© SecPod Technologies