{"api_version":"1","generated_at":"2026-07-23T06:05:51+00:00","cve":"CVE-2008-1283","urls":{"html":"https://cve.report/CVE-2008-1283","api":"https://cve.report/api/cve/CVE-2008-1283.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-1283","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-1283"},"summary":{"title":"CVE-2008-1283","description":"Cross-site scripting (XSS) vulnerability in Neptune Web Server 3.0 allows remote attackers to inject arbitrary web script or HTML via the URI, which is not properly handled in the 404 error page.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-03-11 00:44:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/41089","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/41089","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/28148","name":"http://www.securityfocus.com/bid/28148","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Neptune Web Server 404 Error Page Cross Site Scripting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://securityreason.com/securityalert/3725","name":"http://securityreason.com/securityalert/3725","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityReason - XSS in Neptune Web Server","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/489282/100/0/threaded","name":"http://www.securityfocus.com/archive/1/489282/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-1283","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-1283","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"1283","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"silver-forge","cpe5":"neptune_web_server","cpe6":"3.0","cpe7":"*","cpe8":"professional","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T08:17:34.093Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"neptune-webserver-404errorpage-xss(41089)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/41089"},{"name":"28148","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/28148"},{"name":"20080307 XSS in Neptune Web Server","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/489282/100/0/threaded"},{"name":"3725","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/3725"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-03-07T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in Neptune Web Server 3.0 allows remote attackers to inject arbitrary web script or HTML via the URI, which is not properly handled in the 404 error page."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-11T19:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"neptune-webserver-404errorpage-xss(41089)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/41089"},{"name":"28148","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/28148"},{"name":"20080307 XSS in Neptune Web Server","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/489282/100/0/threaded"},{"name":"3725","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/3725"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-1283","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in Neptune Web Server 3.0 allows remote attackers to inject arbitrary web script or HTML via the URI, which is not properly handled in the 404 error page."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"neptune-webserver-404errorpage-xss(41089)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/41089"},{"name":"28148","refsource":"BID","url":"http://www.securityfocus.com/bid/28148"},{"name":"20080307 XSS in Neptune Web Server","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/489282/100/0/threaded"},{"name":"3725","refsource":"SREASON","url":"http://securityreason.com/securityalert/3725"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-1283","datePublished":"2008-03-11T00:00:00.000Z","dateReserved":"2008-03-10T00:00:00.000Z","dateUpdated":"2024-08-07T08:17:34.093Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-03-11 00:44:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:silver-forge:neptune_web_server:3.0:*:professional:*:*:*:*:*","matchCriteriaId":"44AB6FB7-5988-4D94-BE8A-D6103BDDB086"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"1283","Ordinal":"1","Title":"CVE-2008-1283","CVE":"CVE-2008-1283","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"1283","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in Neptune Web Server 3.0 allows remote attackers to inject arbitrary web script or HTML via the URI, which is not properly handled in the 404 error page.","Type":"Description","Title":"CVE-2008-1283"},{"CveYear":"2008","CveId":"1283","Ordinal":"2","NoteData":"2008-03-10","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"1283","Ordinal":"3","NoteData":"2018-10-11","Type":"Other","Title":"Modified"}]}}}