{"api_version":"1","generated_at":"2026-07-23T11:20:49+00:00","cve":"CVE-2008-0917","urls":{"html":"https://cve.report/CVE-2008-0917","api":"https://cve.report/api/cve/CVE-2008-0917.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-0917","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-0917"},"summary":{"title":"CVE-2008-0917","description":"Cross-site scripting (XSS) vulnerability in Tor World Tor Search 1.1 and earlier, I-Navigator 4.0, Mobile Frontier 2.1 and earlier, Diary.cgi (aka Quotes of the Day) 1.5 and earlier, Tor News 1.21 and earlier, Simple BBS 1.3 and earlier, Interactive BBS 1.3 and earlier, Tor Board 1.1 and earlier, Simple Vote 1.1 and earlier, and Com Vote 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-02-22 23:44:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://jvn.jp/jp/JVN%2354593414/index.html","name":"http://jvn.jp/jp/JVN%2354593414/index.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"JVN#54593414: 複数の Tor World 製 CGI スクリプトにおけるクロスサイトスクリプティングの脆弱性","mime":"text/xml","httpstatus":"200","archivestatus":"404"},{"url":"http://secunia.com/advisories/29039","name":"http://secunia.com/advisories/29039","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Security Advisory SA29039 - Tor World CGI Scripts Multiple Unspecified Cross-Site Scripting Vulnerabilities - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://download.torworld.com/bug/20080221.html","name":"http://download.torworld.com/bug/20080221.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/27919","name":"http://www.securityfocus.com/bid/27919","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Tor World CGI Scripts Unspecified Cross-Site Scripting Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://jvn.jp/jp/JVN#54593414/index.html","name":"JVN:JVN#54593414","refsource":"MITRE","tags":[],"title":"","mime":"text/plain","httpstatus":"404","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-0917","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-0917","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"917","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tor_world","cpe5":"com_vote","cpe6":"1.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"917","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tor_world","cpe5":"i-navigator","cpe6":"4.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"917","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tor_world","cpe5":"interactive_bbs","cpe6":"1.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"917","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tor_world","cpe5":"mobile_frontier","cpe6":"2.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"917","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tor_world","cpe5":"quotes_of_the_day","cpe6":"1.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"917","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tor_world","cpe5":"simple_bbs","cpe6":"1.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"917","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tor_world","cpe5":"simple_vote","cpe6":"1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"917","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tor_world","cpe5":"tor_board","cpe6":"1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"917","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tor_world","cpe5":"tor_news","cpe6":"1.21","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"917","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tor_world","cpe5":"tor_search","cpe6":"1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T08:01:40.151Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://download.torworld.com/bug/20080221.html"},{"name":"29039","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/29039"},{"name":"JVN#54593414","tags":["third-party-advisory","x_refsource_JVN","x_transferred"],"url":"http://jvn.jp/jp/JVN%2354593414/index.html"},{"name":"27919","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/27919"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-02-21T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in Tor World Tor Search 1.1 and earlier, I-Navigator 4.0, Mobile Frontier 2.1 and earlier, Diary.cgi (aka Quotes of the Day) 1.5 and earlier, Tor News 1.21 and earlier, Simple BBS 1.3 and earlier, Interactive BBS 1.3 and earlier, Tor Board 1.1 and earlier, Simple Vote 1.1 and earlier, and Com Vote 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2008-09-24T09:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://download.torworld.com/bug/20080221.html"},{"name":"29039","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/29039"},{"name":"JVN#54593414","tags":["third-party-advisory","x_refsource_JVN"],"url":"http://jvn.jp/jp/JVN%2354593414/index.html"},{"name":"27919","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/27919"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-0917","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in Tor World Tor Search 1.1 and earlier, I-Navigator 4.0, Mobile Frontier 2.1 and earlier, Diary.cgi (aka Quotes of the Day) 1.5 and earlier, Tor News 1.21 and earlier, Simple BBS 1.3 and earlier, Interactive BBS 1.3 and earlier, Tor Board 1.1 and earlier, Simple Vote 1.1 and earlier, and Com Vote 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://download.torworld.com/bug/20080221.html","refsource":"CONFIRM","url":"http://download.torworld.com/bug/20080221.html"},{"name":"29039","refsource":"SECUNIA","url":"http://secunia.com/advisories/29039"},{"name":"JVN#54593414","refsource":"JVN","url":"http://jvn.jp/jp/JVN%2354593414/index.html"},{"name":"27919","refsource":"BID","url":"http://www.securityfocus.com/bid/27919"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-0917","datePublished":"2008-02-22T23:00:00.000Z","dateReserved":"2008-02-22T00:00:00.000Z","dateUpdated":"2024-08-07T08:01:40.151Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-02-22 23:44:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:tor_world:com_vote:1.2:*:*:*:*:*:*:*","matchCriteriaId":"FF561E7A-A089-4958-BC48-73E3B354054B"},{"vulnerable":true,"criteria":"cpe:2.3:a:tor_world:i-navigator:4.0:*:*:*:*:*:*:*","matchCriteriaId":"2F49A46A-71DD-4490-A456-EC14F19AF0F3"},{"vulnerable":true,"criteria":"cpe:2.3:a:tor_world:interactive_bbs:1.3:*:*:*:*:*:*:*","matchCriteriaId":"EBFDCC17-F51F-4322-9EC7-2B434C920282"},{"vulnerable":true,"criteria":"cpe:2.3:a:tor_world:mobile_frontier:2.1:*:*:*:*:*:*:*","matchCriteriaId":"00BA5058-E737-442A-97AC-446E0453FDB6"},{"vulnerable":true,"criteria":"cpe:2.3:a:tor_world:quotes_of_the_day:1.5:*:*:*:*:*:*:*","matchCriteriaId":"79ABA747-8BC3-4830-B4AD-5946062C8A31"},{"vulnerable":true,"criteria":"cpe:2.3:a:tor_world:simple_bbs:1.3:*:*:*:*:*:*:*","matchCriteriaId":"C65B72C5-9C2A-49B4-9292-09B58DD7496E"},{"vulnerable":true,"criteria":"cpe:2.3:a:tor_world:simple_vote:1.1:*:*:*:*:*:*:*","matchCriteriaId":"8264C7DB-A1D9-4072-A252-3E089521442C"},{"vulnerable":true,"criteria":"cpe:2.3:a:tor_world:tor_board:1.1:*:*:*:*:*:*:*","matchCriteriaId":"3D7C4FD4-9402-479C-9986-6C34362F056F"},{"vulnerable":true,"criteria":"cpe:2.3:a:tor_world:tor_news:1.21:*:*:*:*:*:*:*","matchCriteriaId":"7187B8E0-ACBE-4543-9A5C-BCB68114483C"},{"vulnerable":true,"criteria":"cpe:2.3:a:tor_world:tor_search:1.1:*:*:*:*:*:*:*","matchCriteriaId":"015AB9BB-7EAC-4E22-9331-C72D409D8D0B"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"917","Ordinal":"1","Title":"CVE-2008-0917","CVE":"CVE-2008-0917","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"917","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in Tor World Tor Search 1.1 and earlier, I-Navigator 4.0, Mobile Frontier 2.1 and earlier, Diary.cgi (aka Quotes of the Day) 1.5 and earlier, Tor News 1.21 and earlier, Simple BBS 1.3 and earlier, Interactive BBS 1.3 and earlier, Tor Board 1.1 and earlier, Simple Vote 1.1 and earlier, and Com Vote 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.","Type":"Description","Title":"CVE-2008-0917"},{"CveYear":"2008","CveId":"917","Ordinal":"2","NoteData":"2008-02-22","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"917","Ordinal":"3","NoteData":"2008-09-24","Type":"Other","Title":"Modified"}]}}}