Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2008-2196

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

LifeType是一款开放源码的博客平台。 LifeType的admin.php文件中没有正确地过滤对newBlogUserName参数的输入便返回给了用户,如果将Add this user变量设置为Add并将op变量设置为addBlogUser的话,远程攻击者就通过跨站脚本攻击导致在管理员浏览器会话环境中执行任意HTML和脚本代码。

AI Predicted 6.1 Difficulty: Moderate EPSS 1.51% · P72

Public Exploits 1

ExploitDB · 1 EDB-31740 [webapps]
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2008-2196

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Cross-site scripting (XSS) vulnerability in admin.php in LifeType 1.2.8 allows remote attackers to inject arbitrary web script or HTML via the newBlogUserName parameter in an addBlogUser action, a different vector than CVE-2008-2178.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
LifeType newBlogUserName 'admin.php'参数跨站脚本漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
LifeType是一款开放源码的博客平台。 LifeType的admin.php文件中没有正确地过滤对newBlogUserName参数的输入便返回给了用户,如果将Add this user变量设置为Add并将op变量设置为addBlogUser的话,远程攻击者就通过跨站脚本攻击导致在管理员浏览器会话环境中执行任意HTML和脚本代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2008-2196

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2008-2196

登录查看更多情报信息。

Vendor Advisories for CVE-2008-2196 (4)

Other References for CVE-2008-2196 (1)

Same Patch Batch · n/a · 2008-05-14 · 43 CVEs total

CVE-2008-2203 Maian Script World 'search.php' SQL注入漏洞
CVE-2008-2192 iTCms boxpop.php远程文件包含漏洞
CVE-2008-2206 Maian Script World 'index.php'多个跨站脚本攻击漏洞
CVE-2008-2205 Maian Script World 'index.php' SQL注入漏洞
CVE-2008-2207 Maian Script World 'admin/index.php' 跨站脚本攻击漏洞
CVE-2008-2210 Maian Script World 'admin/inc/footer.php' 多个跨站脚本攻击漏洞
CVE-2008-2211 Maian Script World 'admin/inc/footer.php' 多个跨站脚本攻击漏洞
CVE-2008-2212 Maian Script World 'admin/inc/header.php' 多个跨站脚本攻击漏洞
CVE-2008-2213 Maian Script World 'admin/inc/footer.php' 多个跨站脚本攻击漏洞
CVE-2008-2209 Maian Script World 'admin/inc/header.php' 多个跨站脚本攻击漏洞
CVE-2008-2204 Maian Script World 'admin/inc/header.php' 多个跨站脚本攻击漏洞
CVE-2008-2202 Maian Uploader 'upload/admin/index.php' 多个跨站脚本攻击漏洞
CVE-2008-2201 Maian Script World 多个跨站脚本攻击漏洞
CVE-2008-2200 Maian Script World admin/inc/php参数多个跨站脚本攻击漏洞
CVE-2008-2199 Kmita Mail 'htmlcode.php' 远程文件包含漏洞
CVE-2008-2198 Kmita Tellfriend 'htmlcode.php' 远程文件包含漏洞
CVE-2008-2197 Intesync LLC Miniweb 2.0 Blog Writer Module 'historymonth' 参数SQL注入漏洞
CVE-2008-2195 DeluxeBB SQL注入和PHP注入漏洞
CVE-2008-2194 DeluxeBB SQL注入和PHP注入漏洞
CVE-2008-2193 Thomas Gossmann ScorpNews 'example.php' 远程文件包含漏洞

Showing top 20 of 43 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2008-2196

No comments yet


Leave a comment