{"api_version":"1","generated_at":"2026-07-23T11:47:20+00:00","cve":"CVE-2008-4876","urls":{"html":"https://cve.report/CVE-2008-4876","api":"https://cve.report/api/cve/CVE-2008-4876.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-4876","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-4876"},"summary":{"title":"CVE-2008-4876","description":"Cross-site scripting (XSS) vulnerability in the web server component in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and 1.0.4.80 allows remote attackers to inject arbitrary web script or HTML via the request URL, which is not properly handled in a 404 web error page.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-11-01 06:00:01","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/archive/1/488127/100/200/threaded","name":"http://www.securityfocus.com/archive/1/488127/100/200/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/5113","name":"https://www.exploit-db.com/exploits/5113","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Philips VOIP841 (Firmware <= 1.0.4.800) Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2008/0583","name":"http://www.vupen.com/english/advisories/2008/0583","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/4536","name":"http://securityreason.com/securityalert/4536","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Philips VOIP841 Multiple Vulnerabilities - CXSecurity.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/27790","name":"http://www.securityfocus.com/bid/27790","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Philips VOIP841 DECT Phone Multiple Security Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/28978","name":"http://secunia.com/advisories/28978","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Philips VOIP841 Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-4876","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-4876","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"4876","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"philips_electronics","cpe5":"voip841_dect_phone","cpe6":"1.0.4.48","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"4876","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"philips_electronics","cpe5":"voip841_dect_phone","cpe6":"1.0.4.50","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T10:31:27.875Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"5113","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/5113"},{"name":"28978","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/28978"},{"name":"27790","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/27790"},{"name":"ADV-2008-0583","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/0583"},{"name":"20080214 Philips VOIP841 Multiple Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/488127/100/200/threaded"},{"name":"4536","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/4536"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-02-14T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in the web server component in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and 1.0.4.80 allows remote attackers to inject arbitrary web script or HTML via the request URL, which is not properly handled in a 404 web error page."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-11T19:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"5113","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/5113"},{"name":"28978","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/28978"},{"name":"27790","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/27790"},{"name":"ADV-2008-0583","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/0583"},{"name":"20080214 Philips VOIP841 Multiple Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/488127/100/200/threaded"},{"name":"4536","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/4536"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-4876","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in the web server component in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and 1.0.4.80 allows remote attackers to inject arbitrary web script or HTML via the request URL, which is not properly handled in a 404 web error page."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"5113","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/5113"},{"name":"28978","refsource":"SECUNIA","url":"http://secunia.com/advisories/28978"},{"name":"27790","refsource":"BID","url":"http://www.securityfocus.com/bid/27790"},{"name":"ADV-2008-0583","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2008/0583"},{"name":"20080214 Philips VOIP841 Multiple Vulnerabilities","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/488127/100/200/threaded"},{"name":"4536","refsource":"SREASON","url":"http://securityreason.com/securityalert/4536"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-4876","datePublished":"2008-10-31T23:00:00.000Z","dateReserved":"2008-10-31T00:00:00.000Z","dateUpdated":"2024-08-07T10:31:27.875Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-11-01 06:00:01","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:h:philips_electronics:voip841_dect_phone:1.0.4.48:*:*:*:*:*:*:*","matchCriteriaId":"D08A0A05-EF8F-4135-880B-C06707DE3CE3"},{"vulnerable":true,"criteria":"cpe:2.3:h:philips_electronics:voip841_dect_phone:1.0.4.50:*:*:*:*:*:*:*","matchCriteriaId":"F0364FBC-F56D-48CF-8ABB-226F8C01DD2A"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"4876","Ordinal":"1","Title":"CVE-2008-4876","CVE":"CVE-2008-4876","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"4876","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in the web server component in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and 1.0.4.80 allows remote attackers to inject arbitrary web script or HTML via the request URL, which is not properly handled in a 404 web error page.","Type":"Description","Title":"CVE-2008-4876"},{"CveYear":"2008","CveId":"4876","Ordinal":"2","NoteData":"2008-10-31","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"4876","Ordinal":"3","NoteData":"2018-10-11","Type":"Other","Title":"Modified"}]}}}