CVE-2008-6982
NUCLEIDevalcms - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in index.php in devalcms 1.4a allows remote attackers to inject arbitrary web script or HTML via the currentpath parameter.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Khashayar Fereidani · pythonwebappsphp
https://www.exploit-db.com/exploits/6369
Nuclei Templates (1)
Devalcms 1.4a - Cross-Site Scripting
MEDIUMVERIFIEDby arafatansari
References (5)
Scores
EPSS
0.0859
EPSS Percentile
92.4%
Details
CWE
CWE-79
Status
published
Products (1)
devalcms/devalcms
1.4a
Published
Aug 19, 2009
Tracked Since
Feb 18, 2026