Vulnerability Description
Cross-site scripting (XSS) vulnerability in admin/usercheck.php in fuzzylime (cms) before 3.03 allows remote attackers to inject arbitrary web script or HTML via the user parameter to the login form.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fuzzylime | Fuzzylime Cms | 3.0 |
Related Weaknesses (CWE)
References
- http://cms.fuzzylime.co.uk/st/content/download/Patch
- http://secunia.com/advisories/31980PatchVendor Advisory
- http://securityreason.com/securityalert/4303
- http://www.datensalat.eu/~fabian/cve/CVE-2008-3098-fuzzylime-cms.htmlExploit
- http://www.securityfocus.com/archive/1/496589/100/0/threaded
- http://www.securityfocus.com/bid/31306Exploit
- http://www.vupen.com/english/advisories/2008/2650
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45342
- http://cms.fuzzylime.co.uk/st/content/download/Patch
- http://secunia.com/advisories/31980PatchVendor Advisory
- http://securityreason.com/securityalert/4303
- http://www.datensalat.eu/~fabian/cve/CVE-2008-3098-fuzzylime-cms.htmlExploit
- http://www.securityfocus.com/archive/1/496589/100/0/threaded
- http://www.securityfocus.com/bid/31306Exploit
- http://www.vupen.com/english/advisories/2008/2650
FAQ
What is CVE-2008-3098?
CVE-2008-3098 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Cross-site scripting (XSS) vulnerability in admin/usercheck.php in fuzzylime (cms) before 3.03 allows remote attackers to inject arbitrary web script or HTML via the user parameter to the login form.
How severe is CVE-2008-3098?
CVE-2008-3098 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-3098?
Check the references section above for vendor advisories and patch information. Affected products include: Fuzzylime Fuzzylime Cms.