CVE-2008-5814

PHP <5.2.7 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in PHP, possibly 5.2.7 and earlier, when display_errors is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: because of the lack of details, it is unclear whether this is related to CVE-2006-0208.

Scores

EPSS 0.0078
EPSS Percentile 73.4%

Classification

CWE
CWE-79
Status published

Affected Products (50)

php/php < 5.2.7
php/php
php/php
php/php
php/php
php/php
php/php
php/php
php/php
php/php
php/php
php/php
php/php
php/php
php/php
... and 35 more

Timeline

Published Jan 02, 2009
Tracked Since Feb 18, 2026