CVE-2008-6879
Apache Roller - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in Apache Roller 2.3, 3.0, 3.1, and 4.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter in a search action.
References (5)
Scores
EPSS
0.0203
EPSS Percentile
83.6%
Classification
CWE
CWE-79
Status
published
Affected Products (5)
apache/roller
apache/roller
apache/roller
apache/roller
n/a/n/a
Timeline
Published
Jul 30, 2009
Tracked Since
Feb 18, 2026