CVE-2008-1502

EUVD-2022-5304
The _bad_protocol_once function in phpgwapi/inc/class.kses.inc.php in KSES, as used in eGroupWare before 1.4.003, Moodle before 1.8.5, and other products, allows remote attackers to bypass HTML filtering and conduct cross-site scripting (XSS) attacks via a string containing crafted URL protocols.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 77%
Affected Products (NVD)
VendorProductVersion
egroupwareegroupware
𝑥
≤ 1.4.002
egroupwareegroupware
1.0
egroupwareegroupware
1.0.1
egroupwareegroupware
1.0.3
egroupwareegroupware
1.0.6
egroupwareegroupware
1.2.106-2
egroupwareegroupware
1.4.001
moodlemoodle
𝑥
≤ 1.8.4
moodlemoodle
1.1.1
moodlemoodle
1.2.0
moodlemoodle
1.2.1
moodlemoodle
1.3.0
moodlemoodle
1.3.1
moodlemoodle
1.3.2
moodlemoodle
1.3.3
moodlemoodle
1.3.4
moodlemoodle
1.4.1
moodlemoodle
1.4.2
moodlemoodle
1.4.3
moodlemoodle
1.4.4
moodlemoodle
1.4.5
moodlemoodle
1.5
moodlemoodle
1.5.0:beta
moodlemoodle
1.5.1
moodlemoodle
1.5.2
moodlemoodle
1.5.3
moodlemoodle
1.6.0
moodlemoodle
1.6.1
moodlemoodle
1.6.2
moodlemoodle
1.6.3
moodlemoodle
1.6.4
moodlemoodle
1.6.5
moodlemoodle
1.6.6
moodlemoodle
1.6.7
moodlemoodle
1.7.1
moodlemoodle
1.7.2
moodlemoodle
1.7.3
moodlemoodle
1.7.4
moodlemoodle
1.7.5
moodlemoodle
1.7.6
moodlemoodle
1.8.1
moodlemoodle
1.8.2
moodlemoodle
1.8.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
wordpress
bookworm
6.1.6+dfsg1-0+deb12u1
fixed
bookworm (security)
6.1.6+dfsg1-0+deb12u1
fixed
bullseye
5.7.11+dfsg1-0+deb11u1
fixed
bullseye (security)
5.7.11+dfsg1-0+deb11u1
fixed
sid
6.6.1+dfsg1-1
fixed
trixie
6.6.1+dfsg1-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
egroupware
dapper
ignored
edgy
ignored
feisty
ignored
gutsy
ignored
hardy
Fixed 1.2.107-2.dfsg-2ubuntu1
released
intrepid
not-affected
jaunty
not-affected
karmic
not-affected
moodle
dapper
ignored
edgy
ignored
feisty
ignored
gutsy
Fixed 1.8.2-1ubuntu2.1
released
hardy
Fixed 1.8.2-1ubuntu4.1
released
intrepid
Fixed 1.8.2-1ubuntu2.1
released
jaunty
Fixed 1.8.2-1ubuntu2.1
released
karmic
Fixed 1.8.2-1ubuntu2.1
released
References