CVE-2008-3353

Pure Software Lore <1.7.0 - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in Pure Software Lore before 1.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the (1) article comments feature and the (2) search log feature.

Scores

EPSS 0.0029
EPSS Percentile 51.6%

Classification

CWE
CWE-79
Status draft

Affected Products (32)

puresw/lore < 1.6.3
puresw/lore
puresw/lore
puresw/lore
puresw/lore
puresw/lore
puresw/lore
puresw/lore
puresw/lore
puresw/lore
puresw/lore
puresw/lore
puresw/lore
puresw/lore
puresw/lore
... and 17 more

Timeline

Published Jul 28, 2008
Tracked Since Feb 18, 2026