CVE-2008-3937
CVE-2008-3937
Multiple cross-site scripting (XSS) vulnerabilities in Open Media Collectors Database (OpenDb) 1.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) user_id parameter in an edit action to user_admin.php, the (2) title parameter to listings.php, and the (3) redirect_url parameter to user_profile.php.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected products
n/a · n/apublic PoCs found — 4
cve_referencepacketstorm.linuxsecurity.com/0808-exploits/omcd-xssxsrf.txtunverifiedexploitdbwww.exploit-db.com/exploits/32314unverifiedexploitdbwww.exploit-db.com/exploits/32313unverifiedexploitdbwww.exploit-db.com/exploits/32315unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →