CVE-2008-5225
Xerox DocuShare 6 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in Xerox DocuShare 6 and earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) SearchResults/ and (2) Services/ in dsdn/dsweb/, and (3) the default URI under unspecified docushare/dsweb/ServicesLib/Group-#/ directories.
Exploits (3)
References (10)
Scores
EPSS
0.0359
EPSS Percentile
87.6%
Classification
CWE
CWE-79
Status
published
Affected Products (8)
xerox/docushare
< 6
xerox/docushare
xerox/docushare
xerox/docushare
xerox/docushare
xerox/docushare
xerox/docushare
n/a/n/a
Timeline
Published
Nov 25, 2008
Tracked Since
Feb 18, 2026