{"api_version":"1","generated_at":"2026-07-23T10:40:02+00:00","cve":"CVE-2008-4053","urls":{"html":"https://cve.report/CVE-2008-4053","api":"https://cve.report/api/cve/CVE-2008-4053.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-4053","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-4053"},"summary":{"title":"CVE-2008-4053","description":"Multiple cross-site scripting (XSS) vulnerabilities in index.php in the Bluemoon PopnupBLOG module 3.20 and 3.30 for XOOPS allow remote attackers to inject arbitrary web script or HTML via the (1) param, (2) cat_id, and (3) view parameters.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-09-11 21:06:48","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/30827","name":"http://www.securityfocus.com/bid/30827","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Bluemoon inc. PopnupBlog 'index.php' Multiple Cross-Site Scripting Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://lostmon.blogspot.com/2008/08/popnupblog-indexphp-multiple-variables.html","name":"http://lostmon.blogspot.com/2008/08/popnupblog-indexphp-multiple-variables.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"PopnupBlog index.php multiple variables XSS","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44680","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44680","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/31625","name":"http://secunia.com/advisories/31625","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Xoops PopnupBlog Module \"index.php\" Cross-Site Scripting - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-4053","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-4053","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"4053","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"bluemoon","cpe5":"popnupblog","cpe6":"3.20","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"4053","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"bluemoon","cpe5":"popnupblog","cpe6":"3.30","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"4053","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"xoops","cpe5":"xoops","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T10:00:42.469Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"xoops-popnupblog-index-xss(44680)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44680"},{"name":"31625","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/31625"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://lostmon.blogspot.com/2008/08/popnupblog-indexphp-multiple-variables.html"},{"name":"30827","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/30827"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-08-25T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in index.php in the Bluemoon PopnupBLOG module 3.20 and 3.30 for XOOPS allow remote attackers to inject arbitrary web script or HTML via the (1) param, (2) cat_id, and (3) view parameters."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-07T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"xoops-popnupblog-index-xss(44680)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44680"},{"name":"31625","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/31625"},{"tags":["x_refsource_MISC"],"url":"http://lostmon.blogspot.com/2008/08/popnupblog-indexphp-multiple-variables.html"},{"name":"30827","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/30827"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-4053","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in index.php in the Bluemoon PopnupBLOG module 3.20 and 3.30 for XOOPS allow remote attackers to inject arbitrary web script or HTML via the (1) param, (2) cat_id, and (3) view parameters."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"xoops-popnupblog-index-xss(44680)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44680"},{"name":"31625","refsource":"SECUNIA","url":"http://secunia.com/advisories/31625"},{"name":"http://lostmon.blogspot.com/2008/08/popnupblog-indexphp-multiple-variables.html","refsource":"MISC","url":"http://lostmon.blogspot.com/2008/08/popnupblog-indexphp-multiple-variables.html"},{"name":"30827","refsource":"BID","url":"http://www.securityfocus.com/bid/30827"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-4053","datePublished":"2008-09-11T14:00:00.000Z","dateReserved":"2008-09-11T00:00:00.000Z","dateUpdated":"2024-08-07T10:00:42.469Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-09-11 21:06:48","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:bluemoon:popnupblog:3.20:*:*:*:*:*:*:*","matchCriteriaId":"395002B3-746B-4385-B0C7-5F3A6CA40179"},{"vulnerable":true,"criteria":"cpe:2.3:a:bluemoon:popnupblog:3.30:*:*:*:*:*:*:*","matchCriteriaId":"40CFC30D-9179-4787-B991-BBC0CC0112B0"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:a:xoops:xoops:*:*:*:*:*:*:*:*","matchCriteriaId":"EB325E21-BD1E-4C12-B3B1-7210AFFD1235"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"4053","Ordinal":"1","Title":"CVE-2008-4053","CVE":"CVE-2008-4053","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"4053","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in index.php in the Bluemoon PopnupBLOG module 3.20 and 3.30 for XOOPS allow remote attackers to inject arbitrary web script or HTML via the (1) param, (2) cat_id, and (3) view parameters.","Type":"Description","Title":"CVE-2008-4053"},{"CveYear":"2008","CveId":"4053","Ordinal":"2","NoteData":"2008-09-11","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"4053","Ordinal":"3","NoteData":"2017-08-07","Type":"Other","Title":"Modified"}]}}}