CVE-2008-2397
21.05.2008, 13:24
Cross-site scripting (XSS) vulnerability in search-results.dot in dotCMS 1.x allows remote attackers to inject arbitrary web script or HTML via the search_query parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Vendor | Product | Version |
---|---|---|
dotcms | dotcms | 1.0 |
dotcms | dotcms | 1.2.0 |
dotcms | dotcms | 1.5.0 |
dotcms | dotcms | 1.5.1 |
dotcms | dotcms | 1.5.1.1 |
dotcms | dotcms | 1.6 |
dotcms | dotcms | 1.6:rc1 |
dotcms | dotcms | 1.6:rc2 |
dotcms | dotcms | 1.6:rc3 |
dotcms | dotcms | 1.6.0.1 |
dotcms | dotcms | 1.6.0.2 |
dotcms | dotcms | 1.6.0.3 |
dotcms | dotcms | 1.6.0.4 |
𝑥
= Vulnerable software versions