CVE-2008-5918
NONE
Published Jan 21, 200917y ago · Modified Jun 16, 20262w ago
Published Jan 21, 2009 17y ago
Last Modified Jun 16, 2026 2w ago
Description
Cross-site scripting (XSS) vulnerability in the getParameterisedSelfUrl function in index.php in WebSVN 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
Threat Intelligence
No active exploitation signals — not in CISA KEV and no EPSS score yet.
Exploit & Patch Status
Public Exploit Known
Patch Available
Weaknesses 1
CWE-79 Cross-site Scripting Injection
Affected Products 20
| Vendor | Product | Version | Range |
|---|---|---|---|
| tigris | websvn | * | ≤2.0 |
| tigris | websvn | 1.00 | any |
| tigris | websvn | 1.01 | any |
| tigris | websvn | 1.02 | any |
| tigris | websvn | 1.03 | any |
| tigris | websvn | 1.04 | any |
| tigris | websvn | 1.10 | any |
| tigris | websvn | 1.20 | any |
| tigris | websvn | 1.31a | any |
| tigris | websvn | 1.32 | any |
| tigris | websvn | 1.33 | any |
| tigris | websvn | 1.34 | any |
| tigris | websvn | 1.37 | any |
| tigris | websvn | 1.38 | any |
| tigris | websvn | 1.39 | any |
| tigris | websvn | 1.40 | any |
| tigris | websvn | 1.51 | any |
| tigris | websvn | 1.60 | any |
| tigris | websvn | 1.61 | any |
| tigris | websvn | 1.62 | any |
References 10
- secunia.com http://secunia.com/advisories/32338
- secunia.com http://secunia.com/advisories/34191
- securityreason.com http://securityreason.com/securityalert/4928
- websvn.tigris.org http://websvn.tigris.org/issues/show_bug.cgi?id=179
- websvn.tigris.org http://websvn.tigris.org/servlets/NewsItemView?newsItemID=2218
- gentoo.org http://www.gentoo.org/security/en/glsa/glsa-200903-20.xml
- gulftech.org http://www.gulftech.org/?node=research&article_id=00132-10202008
- securityfocus.com http://www.securityfocus.com/bid/31891
- exchange.xforce.ibmcloud.com https://exchange.xforce.ibmcloud.com/vulnerabilities/46048
- exploit-db.com https://www.exploit-db.com/exploits/6822
Remediation
- websvn.tigris.org http://websvn.tigris.org/servlets/NewsItemView?newsItemID=2218