Vulnerability Description
Cross-site scripting (XSS) vulnerability in userlist.php in PunBB before 1.2.20 allows remote attackers to inject arbitrary web script or HTML via the p parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Punbb | Punbb | <= 1.2.19 |
Related Weaknesses (CWE)
References
- http://punbb.informer.com/download/changelogs/1.2.19_to_1.2.20.txt
- http://punbb.informer.com/forums/topic/19682/punbb-1220-and-13rc-hotfix-released
- http://www.openwall.com/lists/oss-security/2008/09/09/10
- http://www.openwall.com/lists/oss-security/2008/09/09/2
- http://www.securityfocus.com/bid/31082
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45046
- http://punbb.informer.com/download/changelogs/1.2.19_to_1.2.20.txt
- http://punbb.informer.com/forums/topic/19682/punbb-1220-and-13rc-hotfix-released
- http://www.openwall.com/lists/oss-security/2008/09/09/10
- http://www.openwall.com/lists/oss-security/2008/09/09/2
- http://www.securityfocus.com/bid/31082
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45046
FAQ
What is CVE-2008-3968?
CVE-2008-3968 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Cross-site scripting (XSS) vulnerability in userlist.php in PunBB before 1.2.20 allows remote attackers to inject arbitrary web script or HTML via the p parameter.
How severe is CVE-2008-3968?
CVE-2008-3968 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-3968?
Check the references section above for vendor advisories and patch information. Affected products include: Punbb Punbb.