CVE-2008-0207
Pro Search < 0.17 - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in PRO-Search 0.17 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) prot, (2) host, (3) path, (4) name, (5) ext, (6) size, (7) search_days, or (8) show_page parameter to the default URI.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by MustLive · textwebappsphp
https://www.exploit-db.com/exploits/30981
References (8)
Scores
EPSS
0.0078
EPSS Percentile
73.5%
Classification
CWE
CWE-79
Status
draft
Affected Products (1)
pro_search/pro_search
< 0.17
Timeline
Published
Jan 10, 2008
Tracked Since
Feb 18, 2026