CVE-2008-4432

Rmsoft Minishop Module - XSS

Title source: rule
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in search.php in the RMSOFT MiniShop module 1.0 for Xoops allows remote attackers to inject arbitrary web script or HTML via the itemsxpag parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Lostmon · textwebappsphp
https://www.exploit-db.com/exploits/32196

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/44374
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/30616

Scores

EPSS 0.0161
EPSS Percentile 81.8%

Details

CWE
CWE-79
Status published
Products (1)
rmsoft/minishop_module 1.0
Published Oct 03, 2008
Tracked Since Feb 18, 2026