CVE-2008-1414
Multiple Time Sheets <5.0 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in Multiple Time Sheets (MTS) 5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the tab parameter to (1) index.php, as demonstrated using mixed case and encoded whitespace characters in the tag; or (2) clientinfo.php, (3) invoices.php, (4) smartlinks.php, and (5) todo.php, as demonstrated using a META tag.
Exploits (1)
References (7)
Scores
EPSS
0.0789
EPSS Percentile
91.9%
Classification
CWE
CWE-79
Status
draft
Affected Products (1)
riceball/multiple_time_sheets
Timeline
Published
Mar 20, 2008
Tracked Since
Feb 18, 2026