Vulnerability Description
Cross-site scripting (XSS) vulnerability in FreeStyle Wiki 3.6.2 and earlier, and 3.6.3 dev3 and earlier development versions, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2005-1799.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fswiki | Freestyle Wiki | <= 3.6.2 |
| Microsoft | Internet Explorer | All versions |
Related Weaknesses (CWE)
References
- http://fswiki.org/wiki.pl?page=%CD%FA%CE%F2%2F2008-7-3
- http://jvn.jp/en/jp/JVN77432756/index.htmlThird Party Advisory
- http://jvn.jp/jp/JVN77432756/index.htmlThird Party Advisory
- http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000036.htmlThird Party AdvisoryVDB Entry
- http://secunia.com/advisories/30923Vendor Advisory
- http://www.securityfocus.com/bid/30071Third Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43574Third Party AdvisoryVDB Entry
- http://fswiki.org/wiki.pl?page=%CD%FA%CE%F2%2F2008-7-3
- http://jvn.jp/en/jp/JVN77432756/index.htmlThird Party Advisory
- http://jvn.jp/jp/JVN77432756/index.htmlThird Party Advisory
- http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000036.htmlThird Party AdvisoryVDB Entry
- http://secunia.com/advisories/30923Vendor Advisory
- http://www.securityfocus.com/bid/30071Third Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43574Third Party AdvisoryVDB Entry
FAQ
What is CVE-2008-3023?
CVE-2008-3023 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Cross-site scripting (XSS) vulnerability in FreeStyle Wiki 3.6.2 and earlier, and 3.6.3 dev3 and earlier development versions, when Internet Explorer is used, allows remote attackers to inject arbitra...
How severe is CVE-2008-3023?
CVE-2008-3023 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-3023?
Check the references section above for vendor advisories and patch information. Affected products include: Fswiki Freestyle Wiki, Microsoft Internet Explorer.