CVE-2008-2188

Multiple cross-site scripting (XSS) vulnerabilities in EJ3 BlackBook 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) bookCopyright and (2) ver parameters to (a) footer.php, and the (3) bookName, (4) bookMetaTags, and (5) estiloCSS parameters to (b) header.php.
Configurations

Configuration 1 (hide)

cpe:2.3:a:eejj33:blackbook:1.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2008-05-13 22:20

Updated : 2024-02-04 17:33


NVD link : CVE-2008-2188

Mitre link : CVE-2008-2188

CVE.ORG link : CVE-2008-2188


JSON object : View

Products Affected

eejj33

  • blackbook
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')