CVE-2008-7171
LNP 1.0b - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in Lightweight news portal (LNP) 1.0b allow remote attackers to inject arbitrary web script or HTML via the (1) photo parameter to show_photo.php, (2) potd parameter to show_potd.php, or (3) the Current question field in a vote action to admin.php.
Exploits (1)
References (4)
Scores
EPSS
0.0227
EPSS Percentile
84.4%
Classification
CWE
CWE-79
Status
published
Affected Products (2)
yanick_bourbeau/lightweight_news_portal
n/a/n/a
Timeline
Published
Sep 08, 2009
Tracked Since
Feb 18, 2026