CVE-2008-5338

Bandwebsite 1.5 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in info.php in Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to inject arbitrary web script or HTML via the section parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by ZoRLu · textwebappsphp
https://www.exploit-db.com/exploits/7215

Scores

EPSS 0.0329
EPSS Percentile 87.0%

Classification

CWE
CWE-79
Status published

Affected Products (3)

multimania/bandsite_portal_system
multimania/bandwebsite
n/a/n/a

Timeline

Published Dec 05, 2008
Tracked Since Feb 18, 2026