{"api_version":"1","generated_at":"2026-07-23T06:02:55+00:00","cve":"CVE-2008-10001","urls":{"html":"https://cve.report/CVE-2008-10001","api":"https://cve.report/api/cve/CVE-2008-10001.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-10001","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-10001"},"summary":{"title":"CVE-2008-10001","description":"** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as problematic, has been found in Pro2col Stingray FTS. The manipulation of the argument Username leads to cross site scripting. The attack may be initiated remotely. It is recommended to upgrade the affected component. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.","state":"PUBLIC","assigner":"cna@vuldb.com","published_at":"2022-03-28 21:15:00","updated_at":"2023-11-07 02:01:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"http://seclists.org/bugtraq/2008/Sep/0157.html","name":"http://seclists.org/bugtraq/2008/Sep/0157.html","refsource":"MISC","tags":[],"title":"Bugtraq: [scip_Advisory 3809] Pro2col StingRay FTS login username cross site scripting","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://vuldb.com/?id.3809","name":"https://vuldb.com/?id.3809","refsource":"MISC","tags":[],"title":"VDB-3809 | Pro2col Stingray FTS cross site scriting (by scip AG)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-10001","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-10001","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"10001","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"pro2col","cpe5":"stingray_fts","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2008-10001","TITLE":"Pro2col Stingray FTS cross site scriting","REQUESTER":"cna@vuldb.com","ASSIGNER":"cna@vuldb.com","STATE":"PUBLIC"},"generator":"vuldb.com","affects":{"vendor":{"vendor_data":[{"vendor_name":"Pro2col","product":{"product_data":[{"product_name":"Stingray FTS","version":{"version_data":[{"version_value":"n/a"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-80 Basic Cross Site Scripting"}]}]},"description":{"description_data":[{"lang":"eng","value":"** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as problematic, has been found in Pro2col Stingray FTS. The manipulation of the argument Username leads to cross site scripting. The attack may be initiated remotely. It is recommended to upgrade the affected component. NOTE: This vulnerability only affects products that are no longer supported by the maintainer."}]},"credit":"Marc Ruef","impact":{"cvss":{"version":"3.1","baseScore":"5.5","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L"}},"references":{"reference_data":[{"url":"https://vuldb.com/?id.3809","refsource":"MISC","name":"https://vuldb.com/?id.3809"},{"url":"http://seclists.org/bugtraq/2008/Sep/0157.html","refsource":"MISC","name":"http://seclists.org/bugtraq/2008/Sep/0157.html"}]}},"nvd":{"publishedDate":"2022-03-28 21:15:00","lastModifiedDate":"2023-11-07 02:01:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:pro2col:stingray_fts:-:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"10001","Ordinal":"227339","Title":"CVE-2008-10001","CVE":"CVE-2008-10001","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"10001","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}