{"api_version":"1","generated_at":"2026-07-23T11:56:59+00:00","cve":"CVE-2008-2567","urls":{"html":"https://cve.report/CVE-2008-2567","api":"https://cve.report/api/cve/CVE-2008-2567.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-2567","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-2567"},"summary":{"title":"CVE-2008-2567","description":"Cross-site scripting (XSS) vulnerability in Fenriru Sleipnir 2.7.1 Release2 and earlier, Portable Sleipnir 2.7.1 Release2 and earlier, and Grani 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to a history mechanism and favorites search, a different vulnerability than CVE-2007-6002.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-06-06 18:32:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://jvn.jp/jp/JVN25448394/index.html","name":"http://jvn.jp/jp/JVN25448394/index.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"JVN#25448394: Sleipnir および Grani のお気に入り検索結果を履歴より復元した際に任意のスクリプトが実行される脆弱性","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://www.fenrir.co.jp/sleipnir/note.html","name":"http://www.fenrir.co.jp/sleipnir/note.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Sleipnir | リリースノート","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/29555","name":"http://www.securityfocus.com/bid/29555","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Sleipnir 'favorite search' Function Script Code Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/30487","name":"http://secunia.com/advisories/30487","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Sleipnir Script Execution Vulnerability - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/42827","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/42827","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-2567","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-2567","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"2567","vulnerable":"1","versionEndIncluding":"3.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"fenrir","cpe5":"grani","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T09:05:30.190Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"JVN#25448394","tags":["third-party-advisory","x_refsource_JVN","x_transferred"],"url":"http://jvn.jp/jp/JVN25448394/index.html"},{"name":"29555","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/29555"},{"name":"30487","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/30487"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.fenrir.co.jp/sleipnir/note.html"},{"name":"sleipnir-favoritesearch-xss(42827)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/42827"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-06-04T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in Fenriru Sleipnir 2.7.1 Release2 and earlier, Portable Sleipnir 2.7.1 Release2 and earlier, and Grani 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to a history mechanism and favorites search, a different vulnerability than CVE-2007-6002."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-07T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"JVN#25448394","tags":["third-party-advisory","x_refsource_JVN"],"url":"http://jvn.jp/jp/JVN25448394/index.html"},{"name":"29555","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/29555"},{"name":"30487","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/30487"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.fenrir.co.jp/sleipnir/note.html"},{"name":"sleipnir-favoritesearch-xss(42827)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/42827"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-2567","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in Fenriru Sleipnir 2.7.1 Release2 and earlier, Portable Sleipnir 2.7.1 Release2 and earlier, and Grani 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to a history mechanism and favorites search, a different vulnerability than CVE-2007-6002."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"JVN#25448394","refsource":"JVN","url":"http://jvn.jp/jp/JVN25448394/index.html"},{"name":"29555","refsource":"BID","url":"http://www.securityfocus.com/bid/29555"},{"name":"30487","refsource":"SECUNIA","url":"http://secunia.com/advisories/30487"},{"name":"http://www.fenrir.co.jp/sleipnir/note.html","refsource":"CONFIRM","url":"http://www.fenrir.co.jp/sleipnir/note.html"},{"name":"sleipnir-favoritesearch-xss(42827)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/42827"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-2567","datePublished":"2008-06-06T18:00:00.000Z","dateReserved":"2008-06-06T00:00:00.000Z","dateUpdated":"2024-08-07T09:05:30.190Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-06-06 18:32:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:fenrir:grani:*:*:*:*:*:*:*:*","versionEndIncluding":"3.1","matchCriteriaId":"9FEC60B3-254C-4DAE-89A3-56AFB4C448ED"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"2567","Ordinal":"1","Title":"CVE-2008-2567","CVE":"CVE-2008-2567","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"2567","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in Fenriru Sleipnir 2.7.1 Release2 and earlier, Portable Sleipnir 2.7.1 Release2 and earlier, and Grani 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to a history mechanism and favorites search, a different vulnerability than CVE-2007-6002.","Type":"Description","Title":"CVE-2008-2567"},{"CveYear":"2008","CveId":"2567","Ordinal":"2","NoteData":"2008-06-06","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"2567","Ordinal":"3","NoteData":"2017-08-07","Type":"Other","Title":"Modified"}]}}}