PoC Index

CVE-2008-3326

LOW 2.6EPSS 2.4%

Cross-site scripting (XSS) vulnerability in blog/edit.php in Moodle 1.6.x before 1.6.7 and 1.7.x before 1.7.5 allows remote attackers to inject arbitrary web script or HTML via the etitle parameter (blog entry title).

CVSS v2.0
2.6 LOWAV:N/AC:H/Au:N/C:N/I:P/A:N
EPSS
2.39% chance of exploitation in the next 30 days, 83th percentile
Published
2008-07-25
Updated
2024-08-07

Proof-of-concept exploits (1)

References

Related