CVE-2008-3316
Summary
| CVE | CVE-2008-3316 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-07-25 16:41:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Cross-site scripting (XSS) vulnerability in the search feature in the Forum plugin before 2.7.1 for Geeklog allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably related to (1) public_html/index.php, (2) config.php, and (3) functions.inc. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Portalparts | Forum Plugin | 2.3.1 | All | geeklog | All |
| Application | Portalparts | Forum Plugin | All | All | geeklog | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Geeklog Forum Plugin Search Cross-Site Scripting Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Geeklog Forum Plugin Cross-Site Scripting Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| JVN#60419863 Geeklog Forum Plugin vulnerable to cross-site scripting | af854a3a-2127-422b-91ae-364da2661108 | jvn.jp | |
| jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000045.html | af854a3a-2127-422b-91ae-364da2661108 | jvndb.jvn.jp | |
| Forum Plugin Version 2.7.1 - Security Fix - Geeklog | af854a3a-2127-422b-91ae-364da2661108 | www.geeklog.net | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.