CVE-2008-2398

Cross-site scripting (XSS) vulnerability in index.php in AppServ Open Project 2.5.10 and earlier allows remote attackers to inject arbitrary web script or HTML via the appservlang parameter.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 72%
VendorProductVersion
appserv_open_projectappserv
𝑥
≤ 2.5.10
appserv_open_projectappserv
1.0.0
appserv_open_projectappserv
1.2.0
appserv_open_projectappserv
1.3.0
appserv_open_projectappserv
1.4.0
appserv_open_projectappserv
1.5.0
appserv_open_projectappserv
1.6.0
appserv_open_projectappserv
1.7.0
appserv_open_projectappserv
1.8.0
appserv_open_projectappserv
1.9.0
appserv_open_projectappserv
2.0.0
appserv_open_projectappserv
2.1.0
appserv_open_projectappserv
2.2.0
appserv_open_projectappserv
2.3.0
appserv_open_projectappserv
2.4
appserv_open_projectappserv
2.4.1
appserv_open_projectappserv
2.4.2
appserv_open_projectappserv
2.4.3
appserv_open_projectappserv
2.4.4
appserv_open_projectappserv
2.4.4a:a
appserv_open_projectappserv
2.4.5
appserv_open_projectappserv
2.4.6
appserv_open_projectappserv
2.4.7
appserv_open_projectappserv
2.4.8
appserv_open_projectappserv
2.4.9
appserv_open_projectappserv
2.5
appserv_open_projectappserv
2.5.1
appserv_open_projectappserv
2.5.2
appserv_open_projectappserv
2.5.3
appserv_open_projectappserv
2.5.4
appserv_open_projectappserv
2.5.4a:a
appserv_open_projectappserv
2.5.5
appserv_open_projectappserv
2.5.6
appserv_open_projectappserv
2.5.7
appserv_open_projectappserv
2.5.8
appserv_open_projectappserv
2.5.9
𝑥
= Vulnerable software versions