CVE-2008-6144

Typo3 Wec Discussion Forum < 1.7.0 - XSS

Title source: rule

Description

Multiple cross-site scripting (XSS) vulnerabilities in the WEC Discussion Forum (wec_discussion) extension 1.7.0 and earlier for TYPO3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2008-3029.

Scores

EPSS 0.0031
EPSS Percentile 53.8%

Classification

CWE
CWE-79
Status published

Affected Products (7)

typo3/wec_discussion_forum < 1.7.0
typo3/wec_discussion_forum
typo3/wec_discussion_forum
typo3/wec_discussion_forum
typo3/wec_discussion_forum
typo3/wec_discussion_forum
n/a/n/a

Timeline

Published Feb 16, 2009
Tracked Since Feb 18, 2026