CVE-2008-2188
Eejj33 Blackbook - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in EJ3 BlackBook 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) bookCopyright and (2) ver parameters to (a) footer.php, and the (3) bookName, (4) bookMetaTags, and (5) estiloCSS parameters to (b) header.php.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by Khashayar Fereidani · textwebappsphp
https://www.exploit-db.com/exploits/31722
exploitdb
WORKING POC
VERIFIED
by Khashayar Fereidani · textwebappsphp
https://www.exploit-db.com/exploits/31721
References (4)
Scores
EPSS
0.0027
EPSS Percentile
49.7%
Classification
CWE
CWE-79
Status
draft
Affected Products (1)
eejj33/blackbook
Timeline
Published
May 13, 2008
Tracked Since
Feb 18, 2026