CVE-2008-0793
Estado: ModificadaMedia (4.3)—
Multiple cross-site scripting (XSS) vulnerabilities in search.asp in Tendenci CMS allow remote attackers to inject arbitrary web script or HTML via the (1) category, (2) searchtext, (3) jobcategoryid, (4) contactcompany, and unspecified other parameters. NOTE: some of these details are obtained from third party information. NOTE: it is not clear whether this affects Tendenci Enterprise Edition in addition to the product's deployment on Tendenci's own server farm. If only the latter was affected, then this issue should not be included in CVE.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N
- Puntuación base: 4.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.06%
- Percentil entre todas las CVEs puntuadas: 64
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-79
Referencias
- http://blog.tendenci.com/2008/02/cross-site-scri.html
- http://holisticinfosec.blogspot.com/2008/02/fastest-fix-in-west-vendors-excellent.html
- http://secunia.com/advisories/28882
- http://www.securityfocus.com/bid/27782
- https://exchange.xforce.ibmcloud.com/vulnerabilities/40477
- http://blog.tendenci.com/2008/02/cross-site-scri.html
- http://holisticinfosec.blogspot.com/2008/02/fastest-fix-in-west-vendors-excellent.html
- http://secunia.com/advisories/28882
- http://www.securityfocus.com/bid/27782
- https://exchange.xforce.ibmcloud.com/vulnerabilities/40477
JSON original (NVD)
Mostrar
{
"id": "CVE-2008-0793",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2008-02-15T02:00:00.000",
"references": [
{
"url": "http://blog.tendenci.com/2008/02/cross-site-scri.html",
"source": "cve@mitre.org"
},
{
"url": "http://holisticinfosec.blogspot.com/2008/02/fastest-fix-in-west-vendors-excellent.html",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/28882",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/27782",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/40477",
"source": "cve@mitre.org"
},
{
"url": "http://blog.tendenci.com/2008/02/cross-site-scri.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://holisticinfosec.blogspot.com/2008/02/fastest-fix-in-west-vendors-excellent.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/28882",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/27782",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/40477",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple cross-site scripting (XSS) vulnerabilities in search.asp in Tendenci CMS allow remote attackers to inject arbitrary web script or HTML via the (1) category, (2) searchtext, (3) jobcategoryid, (4) contactcompany, and unspecified other parameters. NOTE: some of these details are obtained from third party information. NOTE: it is not clear whether this affects Tendenci Enterprise Edition in addition to the product's deployment on Tendenci's own server farm. If only the latter was affected, then this issue should not be included in CVE."
},
{
"lang": "es",
"value": "Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en search.asp en Tendenci CMS permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección mediante los parámetros (1) category, (2) searchtext, (3) jobcategoryid, (4) contactcompany y otros parámetros no especificados. NOTA: Algunos de estos detalles se han obtenido de información de terceros. NOTA: No está claro si esto afecta a Tendenci Enterprise Edition incluidos en el desarrollo de productos de la propia granja de servidores de Tendenci. Si sólo lo último es lo que resulta afectado, esta vulnerabilidad no debería estar incluida en el CVE."
}
],
"lastModified": "2026-06-16T22:50:22.067",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:tendenci:cms:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A7123A5B-F8EC-46CB-AE6E-6AFE17D0B50F"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}