Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2008-1888Cross-site Scripting in Microsoft Sharepoint Server

Severity
4.3MEDIUMNVD
EPSS
25.0%
top 3.83%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedApr 18
Latest updateMay 1

Description

Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 2.0 allows remote attackers to inject arbitrary web script or HTML via the Picture Source (aka picture object source) field in the Rich Text Editor.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-6mv6-6g96-82f9: Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 22022-05-01
CVEList
CVE-2008-1888: Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 22008-04-18

💥Exploits & PoCs

1
Exploit-DB
Microsoft SharePoint Server 2.0 - Picture Source HTML Injection2008-04-09
CVE-2008-1888 — Cross-site Scripting in Microsoft | cvebase