{"api_version":"1","generated_at":"2026-07-23T08:47:26+00:00","cve":"CVE-2008-0558","urls":{"html":"https://cve.report/CVE-2008-0558","api":"https://cve.report/api/cve/CVE-2008-0558.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-0558","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-0558"},"summary":{"title":"CVE-2008-0558","description":"Cross-site scripting (XSS) vulnerability in Uniwin eCart Professional before 2.0.16 allows remote attackers to inject arbitrary web script or HTML via the rp parameter to cartView.asp and unspecified other components.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-02-04 23:00:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://secunia.com/advisories/28735","name":"http://secunia.com/advisories/28735","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Uniwin eCart Professional \"rp\" Cross-Site Scripting Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/27560","name":"http://www.securityfocus.com/bid/27560","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Uniwin eCart Professional 'rp' Cross-Site Scripting Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-0558","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-0558","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"558","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"uniwin","cpe5":"ecart_professional","cpe6":"2.0.11","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"558","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"uniwin","cpe5":"ecart_professional","cpe6":"2.0.12","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"558","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"uniwin","cpe5":"ecart_professional","cpe6":"2.0.14","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"558","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"uniwin","cpe5":"ecart_professional","cpe6":"2.0.15","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T07:46:54.877Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"27560","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/27560"},{"name":"28735","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/28735"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in Uniwin eCart Professional before 2.0.16 allows remote attackers to inject arbitrary web script or HTML via the rp parameter to cartView.asp and unspecified other components.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2008-02-04T22:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"27560","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/27560"},{"name":"28735","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/28735"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-0558","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in Uniwin eCart Professional before 2.0.16 allows remote attackers to inject arbitrary web script or HTML via the rp parameter to cartView.asp and unspecified other components.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"27560","refsource":"BID","url":"http://www.securityfocus.com/bid/27560"},{"name":"28735","refsource":"SECUNIA","url":"http://secunia.com/advisories/28735"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-0558","datePublished":"2008-02-04T22:00:00.000Z","dateReserved":"2008-02-04T00:00:00.000Z","dateUpdated":"2024-09-17T00:22:01.763Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-02-04 23:00:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:uniwin:ecart_professional:2.0.11:*:*:*:*:*:*:*","matchCriteriaId":"5084695E-B65A-4289-B61B-641D448E7D30"},{"vulnerable":true,"criteria":"cpe:2.3:a:uniwin:ecart_professional:2.0.12:*:*:*:*:*:*:*","matchCriteriaId":"BB53715B-00E4-4DFF-B26E-5B7906D11621"},{"vulnerable":true,"criteria":"cpe:2.3:a:uniwin:ecart_professional:2.0.14:*:*:*:*:*:*:*","matchCriteriaId":"2159E9D7-430D-4D80-A130-539A83D0C052"},{"vulnerable":true,"criteria":"cpe:2.3:a:uniwin:ecart_professional:2.0.15:*:*:*:*:*:*:*","matchCriteriaId":"3BBA2D36-6A09-40A4-9A49-2067953D9058"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"558","Ordinal":"1","Title":"CVE-2008-0558","CVE":"CVE-2008-0558","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"558","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in Uniwin eCart Professional before 2.0.16 allows remote attackers to inject arbitrary web script or HTML via the rp parameter to cartView.asp and unspecified other components.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.","Type":"Description","Title":"CVE-2008-0558"},{"CveYear":"2008","CveId":"558","Ordinal":"2","NoteData":"2008-02-04","Type":"Other","Title":"Published"}]}}}