{"api_version":"1","generated_at":"2026-07-23T10:29:53+00:00","cve":"CVE-2008-1888","urls":{"html":"https://cve.report/CVE-2008-1888","api":"https://cve.report/api/cve/CVE-2008-1888.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-1888","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-1888"},"summary":{"title":"CVE-2008-1888","description":"Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 2.0 allows remote attackers to inject arbitrary web script or HTML via the Picture Source (aka picture object source) field in the Rich Text Editor.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-04-18 21:05:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/28706","name":"http://www.securityfocus.com/bid/28706","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft SharePoint Server Picture Source HTML Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securityfocus.com/archive/1/490624/100/0/threaded","name":"http://www.securityfocus.com/archive/1/490624/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.caughq.org/advisories/CAU-2008-0002.txt","name":"http://www.caughq.org/advisories/CAU-2008-0002.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/41934","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/41934","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-1888","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-1888","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"1888","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"sharepoint_server","cpe6":"2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T08:40:58.608Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"28706","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/28706"},{"name":"microsoft-sharepoint-picturesource-xss(41934)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/41934"},{"name":"20080409 CAU-2008-0002: Microsoft Windows SharePoint Services PictureSource XSS","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/490624/100/0/threaded"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.caughq.org/advisories/CAU-2008-0002.txt"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-04-09T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 2.0 allows remote attackers to inject arbitrary web script or HTML via the Picture Source (aka picture object source) field in the Rich Text Editor."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-11T19:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"28706","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/28706"},{"name":"microsoft-sharepoint-picturesource-xss(41934)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/41934"},{"name":"20080409 CAU-2008-0002: Microsoft Windows SharePoint Services PictureSource XSS","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/490624/100/0/threaded"},{"tags":["x_refsource_MISC"],"url":"http://www.caughq.org/advisories/CAU-2008-0002.txt"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-1888","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 2.0 allows remote attackers to inject arbitrary web script or HTML via the Picture Source (aka picture object source) field in the Rich Text Editor."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"28706","refsource":"BID","url":"http://www.securityfocus.com/bid/28706"},{"name":"microsoft-sharepoint-picturesource-xss(41934)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/41934"},{"name":"20080409 CAU-2008-0002: Microsoft Windows SharePoint Services PictureSource XSS","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/490624/100/0/threaded"},{"name":"http://www.caughq.org/advisories/CAU-2008-0002.txt","refsource":"MISC","url":"http://www.caughq.org/advisories/CAU-2008-0002.txt"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-1888","datePublished":"2008-04-18T21:00:00.000Z","dateReserved":"2008-04-18T00:00:00.000Z","dateUpdated":"2024-08-07T08:40:58.608Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-04-18 21:05:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:sharepoint_server:2.0:*:*:*:*:*:*:*","matchCriteriaId":"8127B923-B007-486A-8E61-10BE1E21D8BC"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"1888","Ordinal":"1","Title":"CVE-2008-1888","CVE":"CVE-2008-1888","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"1888","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 2.0 allows remote attackers to inject arbitrary web script or HTML via the Picture Source (aka picture object source) field in the Rich Text Editor.","Type":"Description","Title":"CVE-2008-1888"},{"CveYear":"2008","CveId":"1888","Ordinal":"2","NoteData":"2008-04-18","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"1888","Ordinal":"3","NoteData":"2018-10-11","Type":"Other","Title":"Modified"}]}}}