CVE-2008-6746

EUVD-2008-6706
Cross-site scripting (XSS) vulnerability in the contact display view in Turba Contact Manager H3 before 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the contact name.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 55%
Affected Products (NVD)
VendorProductVersion
hordeturba_h3
𝑥
≤ 2.2
hordeturba_h3
0.0.1
hordeturba_h3
0.0.2
hordeturba_h3
0.0.3
hordeturba_h3
1.0
hordeturba_h3
1.0:rc4
hordeturba_h3
1.1
hordeturba_h3
1.2
hordeturba_h3
1.2.1
hordeturba_h3
1.2.2
hordeturba_h3
1.2.3
hordeturba_h3
1.2.4
hordeturba_h3
1.2.5
hordeturba_h3
2.0
hordeturba_h3
2.0:alpha
hordeturba_h3
2.0:beta
hordeturba_h3
2.0:rc1
hordeturba_h3
2.0:rc2
hordeturba_h3
2.0:rc3
hordeturba_h3
2.0.1
hordeturba_h3
2.0.1:rc1
hordeturba_h3
2.0.2
hordeturba_h3
2.0.3
hordeturba_h3
2.0.3:rc1
hordeturba_h3
2.0.4
hordeturba_h3
2.0.5
hordeturba_h3
2.1
hordeturba_h3
2.1:rc1
hordeturba_h3
2.1.1
hordeturba_h3
2.1.2
hordeturba_h3
2.1.3
hordeturba_h3
2.1.4
hordeturba_h3
2.1.5
hordeturba_h3
2.1.6
hordeturba_h3
2.1.7
hordeturba_h3
2.2:alpha
hordeturba_h3
2.2:rc1
hordeturba_h3
2.2:rc2
hordeturba_h3
2.2:rc3
hordeturba_h3
2.2:rc4
𝑥
= Vulnerable software versions