PoC Index

CVE-2008-6700

MEDIUM 4.3EPSS 1.5%

Multiple cross-site scripting (XSS) vulnerabilities in Butterfly Organizer 2.0.0 allow remote attackers to inject arbitrary web script or HTML via the (1) mytable parameter to view.php, (2) mytable parameter to viewdb2.php, (3) tablehere parameter to category-rename.php, and (4) letter parameter to module-contacts.php.

CVSS v2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
1.51% chance of exploitation in the next 30 days, 73th percentile
Published
2009-04-10
Updated
2024-08-07

ExploitDB entries (1)

References

Related