{"api_version":"1","generated_at":"2026-07-23T07:30:06+00:00","cve":"CVE-2008-3786","urls":{"html":"https://cve.report/CVE-2008-3786","api":"https://cve.report/api/cve/CVE-2008-3786.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-3786","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-3786"},"summary":{"title":"CVE-2008-3786","description":"Cross-site scripting (XSS) vulnerability in index.php in PICTURESPRO Photo Cart 3.9 allows remote attackers to inject arbitrary web script or HTML via the qtitle parameter (aka \"Gallery or event name\" field) in a search action.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-08-26 14:41:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44614","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44614","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2008-August/064046.html","name":"http://lists.grok.org.uk/pipermail/full-disclosure/2008-August/064046.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[Full-Disclosure] Mailing List Charter","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"http://www.securityfocus.com/bid/30798","name":"http://www.securityfocus.com/bid/30798","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"PicturesPro Photo Cart Search Cross-Site Scripting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/31589","name":"http://secunia.com/advisories/31589","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Photo Cart \"qtitle\" Cross-Site Scripting Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-3786","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-3786","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"3786","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"picturespro","cpe5":"picturespro_photo_cart","cpe6":"3.9","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T09:52:59.428Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"30798","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/30798"},{"name":"photocart-gallery-xss(44614)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44614"},{"name":"20080822 Photo Cart 3.9 index.php \"search\" XSS","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2008-August/064046.html"},{"name":"31589","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/31589"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-08-22T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in index.php in PICTURESPRO Photo Cart 3.9 allows remote attackers to inject arbitrary web script or HTML via the qtitle parameter (aka \"Gallery or event name\" field) in a search action."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-07T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"30798","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/30798"},{"name":"photocart-gallery-xss(44614)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44614"},{"name":"20080822 Photo Cart 3.9 index.php \"search\" XSS","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2008-August/064046.html"},{"name":"31589","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/31589"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-3786","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in index.php in PICTURESPRO Photo Cart 3.9 allows remote attackers to inject arbitrary web script or HTML via the qtitle parameter (aka \"Gallery or event name\" field) in a search action."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"30798","refsource":"BID","url":"http://www.securityfocus.com/bid/30798"},{"name":"photocart-gallery-xss(44614)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44614"},{"name":"20080822 Photo Cart 3.9 index.php \"search\" XSS","refsource":"FULLDISC","url":"http://lists.grok.org.uk/pipermail/full-disclosure/2008-August/064046.html"},{"name":"31589","refsource":"SECUNIA","url":"http://secunia.com/advisories/31589"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-3786","datePublished":"2008-08-26T14:06:00.000Z","dateReserved":"2008-08-26T00:00:00.000Z","dateUpdated":"2024-08-07T09:52:59.428Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-08-26 14:41:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:picturespro:picturespro_photo_cart:3.9:*:*:*:*:*:*:*","matchCriteriaId":"5C34D5F0-620F-4AF2-A8E5-A855E7E3180D"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"3786","Ordinal":"1","Title":"CVE-2008-3786","CVE":"CVE-2008-3786","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"3786","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in index.php in PICTURESPRO Photo Cart 3.9 allows remote attackers to inject arbitrary web script or HTML via the qtitle parameter (aka \"Gallery or event name\" field) in a search action.","Type":"Description","Title":"CVE-2008-3786"},{"CveYear":"2008","CveId":"3786","Ordinal":"2","NoteData":"2008-08-26","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"3786","Ordinal":"3","NoteData":"2017-08-07","Type":"Other","Title":"Modified"}]}}}