CVE-2008-0438
published 2008-01-23CVE-2008-0438: Cross-site scripting (XSS) vulnerability in the font rendering functionality in Novemberborn sIFR 2.0.2 allows remote attackers to inject arbitrary web script…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EXPLOIT
EPSS
2.93%
85.3th percentile
Cross-site scripting (XSS) vulnerability in the font rendering functionality in Novemberborn sIFR 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the txt parameter to a Flash (SWF) file, as demonstrated by fonts/FuturaLt.swf.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| novemberborn | sifr | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://novemberborn.net/sifr/2.0.3http://osvdb.org/41006http://securityreason.com/securityalert/3571http://www.procheckup.com/Vulnerability_PR07-38.phphttp://www.securityfocus.com/archive/1/486787/100/0/threadedhttp://www.securityfocus.com/archive/1/486829/100/0/threadedhttp://www.securityfocus.com/archive/1/487585/100/200/threadedhttp://www.securityfocus.com/bid/27394https://exchange.xforce.ibmcloud.com/vulnerabilities/39835http://novemberborn.net/sifr/2.0.3http://osvdb.org/41006http://securityreason.com/securityalert/3571http://www.procheckup.com/Vulnerability_PR07-38.phphttp://www.securityfocus.com/archive/1/486787/100/0/threadedhttp://www.securityfocus.com/archive/1/486829/100/0/threadedhttp://www.securityfocus.com/archive/1/487585/100/200/threadedhttp://www.securityfocus.com/bid/27394https://exchange.xforce.ibmcloud.com/vulnerabilities/39835
2008-01-23
Published