CVE-2008-4535
Ec-cube < 2.1.2a - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in EC-CUBE Ver2 2.1.2a and earlier, EC-CUBE Ver2 Beta(RC) 2.2.0-beta and earlier, and EC-CUBE Community Edition Nighly-Build r17623 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2008-4536 and CVE-2008-4537.
References (6)
Scores
EPSS
0.0047
EPSS Percentile
64.5%
Classification
CWE
CWE-79
Status
published
Affected Products (5)
ec-cube/ec-cube
< 2.1.2a
ec-cube/ec-cube
ec-cube/ec-cube
ec-cube/ec-cube
n/a/n/a
Timeline
Published
Oct 10, 2008
Tracked Since
Feb 18, 2026