Phpwebsite · Phpwebsite · CVE-2008-0092
**Name of the Vulnerable Software and Affected Versions**
phpWebSite version 1.4.0
**Description**
A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML. This is achieved via the `search` parameter in the search module of index.php.
**Recommendations**
For phpWebSite version 1.4.0, consider restricting access to the search module until a fix is available, or avoid using the `search` parameter in the affected API endpoint.