{"api_version":"1","generated_at":"2026-07-23T04:35:35+00:00","cve":"CVE-2008-3316","urls":{"html":"https://cve.report/CVE-2008-3316","api":"https://cve.report/api/cve/CVE-2008-3316.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-3316","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-3316"},"summary":{"title":"CVE-2008-3316","description":"Cross-site scripting (XSS) vulnerability in the search feature in the Forum plugin before 2.7.1 for Geeklog allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably related to (1) public_html/index.php, (2) config.php, and (3) functions.inc.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-07-25 16:41:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://secunia.com/advisories/31188","name":"http://secunia.com/advisories/31188","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Geeklog Forum Plugin Search Cross-Site Scripting Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43971","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43971","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/30355","name":"http://www.securityfocus.com/bid/30355","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Geeklog Forum Plugin Cross-Site Scripting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://jvn.jp/en/jp/JVN60419863/index.html","name":"http://jvn.jp/en/jp/JVN60419863/index.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"JVN#60419863 Geeklog Forum Plugin vulnerable to cross-site scripting","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000045.html","name":"http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000045.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.geeklog.net/article.php/20080719093147449","name":"http://www.geeklog.net/article.php/20080719093147449","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Forum Plugin Version 2.7.1 - Security Fix - Geeklog","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-3316","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-3316","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"3316","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"portalparts","cpe5":"forum_plugin","cpe6":"2.3.1","cpe7":"*","cpe8":"geeklog","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3316","vulnerable":"1","versionEndIncluding":"2.5","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"portalparts","cpe5":"forum_plugin","cpe6":"*","cpe7":"*","cpe8":"geeklog","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T09:37:26.409Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"31188","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/31188"},{"name":"JVN#60419863","tags":["third-party-advisory","x_refsource_JVN","x_transferred"],"url":"http://jvn.jp/en/jp/JVN60419863/index.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.geeklog.net/article.php/20080719093147449"},{"name":"30355","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/30355"},{"name":"forum-search-xss(43971)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43971"},{"name":"JVNDB-2008-000045","tags":["third-party-advisory","x_refsource_JVNDB","x_transferred"],"url":"http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000045.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-07-19T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in the search feature in the Forum plugin before 2.7.1 for Geeklog allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably related to (1) public_html/index.php, (2) config.php, and (3) functions.inc."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-07T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"31188","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/31188"},{"name":"JVN#60419863","tags":["third-party-advisory","x_refsource_JVN"],"url":"http://jvn.jp/en/jp/JVN60419863/index.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.geeklog.net/article.php/20080719093147449"},{"name":"30355","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/30355"},{"name":"forum-search-xss(43971)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43971"},{"name":"JVNDB-2008-000045","tags":["third-party-advisory","x_refsource_JVNDB"],"url":"http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000045.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-3316","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in the search feature in the Forum plugin before 2.7.1 for Geeklog allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably related to (1) public_html/index.php, (2) config.php, and (3) functions.inc."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"31188","refsource":"SECUNIA","url":"http://secunia.com/advisories/31188"},{"name":"JVN#60419863","refsource":"JVN","url":"http://jvn.jp/en/jp/JVN60419863/index.html"},{"name":"http://www.geeklog.net/article.php/20080719093147449","refsource":"CONFIRM","url":"http://www.geeklog.net/article.php/20080719093147449"},{"name":"30355","refsource":"BID","url":"http://www.securityfocus.com/bid/30355"},{"name":"forum-search-xss(43971)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43971"},{"name":"JVNDB-2008-000045","refsource":"JVNDB","url":"http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000045.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-3316","datePublished":"2008-07-25T16:00:00.000Z","dateReserved":"2008-07-25T00:00:00.000Z","dateUpdated":"2024-08-07T09:37:26.409Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-07-25 16:41:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:portalparts:forum_plugin:*:*:geeklog:*:*:*:*:*","versionEndIncluding":"2.5","matchCriteriaId":"1C11EB13-3C2F-47D5-8FCE-FE67FBC686A0"},{"vulnerable":true,"criteria":"cpe:2.3:a:portalparts:forum_plugin:2.3.1:*:geeklog:*:*:*:*:*","matchCriteriaId":"F9D39609-6E51-4B1F-A700-FCC8B2D97E6D"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"3316","Ordinal":"1","Title":"CVE-2008-3316","CVE":"CVE-2008-3316","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"3316","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in the search feature in the Forum plugin before 2.7.1 for Geeklog allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably related to (1) public_html/index.php, (2) config.php, and (3) functions.inc.","Type":"Description","Title":"CVE-2008-3316"},{"CveYear":"2008","CveId":"3316","Ordinal":"2","NoteData":"2008-07-25","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"3316","Ordinal":"3","NoteData":"2017-08-07","Type":"Other","Title":"Modified"}]}}}