CVE-2008-4435
Rmsoft Downloads Plus Module - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in the RMSOFT Downloads Plus (rmdp) module 1.5 and 1.7 for Xoops allow remote attackers to inject arbitrary web script or HTML via the (1) key parameter to search.php and the (2) id parameter to down.php.
Exploits (2)
Scores
EPSS
0.0023
EPSS Percentile
45.9%
Classification
CWE
CWE-79
Status
draft
Affected Products (2)
rmsoft/downloads_plus_module
rmsoft/downloads_plus_module
Timeline
Published
Oct 03, 2008
Tracked Since
Feb 18, 2026