CVE-2008-7271
Eclipse IDE - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in the Help Contents web application (aka the Help Server) in Eclipse IDE, possibly 3.3.2, allow remote attackers to inject arbitrary web script or HTML via (1) the searchWord parameter to help/advanced/searchView.jsp or (2) the workingSet parameter in an add action to help/advanced/workingSetManager.jsp, a different issue than CVE-2010-4647.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by Rob · textremotemultiple
https://www.exploit-db.com/exploits/35242
Scores
EPSS
0.0039
EPSS Percentile
59.5%
Classification
CWE
CWE-79
Status
published
Affected Products (3)
eclipse/eclipse_ide
eclipse/eclipse_ide
n/a/n/a
Timeline
Published
Jan 13, 2011
Tracked Since
Feb 18, 2026