PT-2008-5267 · Opendb · Opendb

CVE-2008-3937

·

Published

2008-09-05

·

Updated

2025-04-03

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenDb version 1.0.6
Description The issue allows remote attackers to inject arbitrary web script or HTML. This can be achieved via the user id parameter in an edit action to "user admin.php", the title parameter to "listings.php", and the redirect url parameter to "user profile.php".
Recommendations For OpenDb version 1.0.6, avoid using the user id parameter in the edit action to "user admin.php", the title parameter to "listings.php", and the redirect url parameter to "user profile.php" until a fix is available. Consider restricting access to these parameters to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-3937

Affected Products

Opendb