CVE-2008-2188

Multiple cross-site scripting (XSS) vulnerabilities in EJ3 BlackBook 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) bookCopyright and (2) ver parameters to (a) footer.php, and the (3) bookName, (4) bookMetaTags, and (5) estiloCSS parameters to (b) header.php.
Configurations

Configuration 1 (hide)

cpe:2.3:a:eejj33:blackbook:1.0:*:*:*:*:*:*:*

Information

Published : 2008-05-13 22:20

Updated : 2018-10-11 20:39


NVD link : CVE-2008-2188

Mitre link : CVE-2008-2188


JSON object : View

Products Affected

eejj33

  • blackbook
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')