CVE-2008-6746

Cross-site scripting (XSS) vulnerability in the contact display view in Turba Contact Manager H3 before 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the contact name.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 55%
VendorProductVersion
hordeturba_h3
𝑥
≤ 2.2
hordeturba_h3
0.0.1
hordeturba_h3
0.0.2
hordeturba_h3
0.0.3
hordeturba_h3
1.0
hordeturba_h3
1.0:rc4
hordeturba_h3
1.1
hordeturba_h3
1.2
hordeturba_h3
1.2.1
hordeturba_h3
1.2.2
hordeturba_h3
1.2.3
hordeturba_h3
1.2.4
hordeturba_h3
1.2.5
hordeturba_h3
2.0
hordeturba_h3
2.0:alpha
hordeturba_h3
2.0:beta
hordeturba_h3
2.0:rc1
hordeturba_h3
2.0:rc2
hordeturba_h3
2.0:rc3
hordeturba_h3
2.0.1
hordeturba_h3
2.0.1:rc1
hordeturba_h3
2.0.2
hordeturba_h3
2.0.3
hordeturba_h3
2.0.3:rc1
hordeturba_h3
2.0.4
hordeturba_h3
2.0.5
hordeturba_h3
2.1
hordeturba_h3
2.1:rc1
hordeturba_h3
2.1.1
hordeturba_h3
2.1.2
hordeturba_h3
2.1.3
hordeturba_h3
2.1.4
hordeturba_h3
2.1.5
hordeturba_h3
2.1.6
hordeturba_h3
2.1.7
hordeturba_h3
2.2:alpha
hordeturba_h3
2.2:rc1
hordeturba_h3
2.2:rc2
hordeturba_h3
2.2:rc3
hordeturba_h3
2.2:rc4
𝑥
= Vulnerable software versions