CVE-2008-3353
Pure Software Lore <1.7.0 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in Pure Software Lore before 1.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the (1) article comments feature and the (2) search log feature.
References (4)
Scores
EPSS
0.0029
EPSS Percentile
51.6%
Classification
CWE
CWE-79
Status
draft
Affected Products (32)
puresw/lore
< 1.6.3
puresw/lore
puresw/lore
puresw/lore
puresw/lore
puresw/lore
puresw/lore
puresw/lore
puresw/lore
puresw/lore
puresw/lore
puresw/lore
puresw/lore
puresw/lore
puresw/lore
... and 17 more
Timeline
Published
Jul 28, 2008
Tracked Since
Feb 18, 2026