CVE-2008-6205 EXPLOIT
4.3
MEDIUM · CVSS 2.0 · EPSS 1.4% (pctl 72)
Patch early
A public exploit exists.
Description
Cross-site scripting (XSS) vulnerability in seeurl.php in Xavier Flahaut URLStreet 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) language, (2) order, and (3) filter parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Scoring
| CVSS | 4.3 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
| EPSS | 1.44% — more likely to be exploited than 72% of all CVEs |
| Weakness | CWE-79 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-02-20 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| xaaaaav38 | urlstreet |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | URLStreet 1.0 - 'seeurl.php' Multiple Cross-Site Scripting Vulnerabilities | 2008-04-07 |
References
- http://downloads.securityfocus.com/vulnerabilities/exploits/28650.html
- http://www.securityfocus.com/bid/28650
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41731
- http://downloads.securityfocus.com/vulnerabilities/exploits/28650.html
- http://www.securityfocus.com/bid/28650
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41731
→ the Explorer · watch your stack · NVD