PT-2008-5267 · Opendb · Opendb

Published

2008-09-05

·

Updated

2025-04-03

·

CVE-2008-3937

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenDb version 1.0.6
Description The issue allows remote attackers to inject arbitrary web script or HTML. This can be achieved via the user id parameter in an edit action to "user admin.php", the title parameter to "listings.php", and the redirect url parameter to "user profile.php".
Recommendations For OpenDb version 1.0.6, avoid using the user id parameter in the edit action to "user admin.php", the title parameter to "listings.php", and the redirect url parameter to "user profile.php" until a fix is available. Consider restricting access to these parameters to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2008-3937

Affected Products

Opendb