.. / CVE-2008-2398

Exploit for AppServ Open Project <=2.5.10 - Cross-Site Scripting (CVE-2008-2398)

Description:

AppServ Open Project 2.5.10 and earlier contains a cross-site scripting vulnerability in index.php which allows remote attackers to inject arbitrary web script or HTML via the appservlang parameter.

Nuclei Template

View the template here CVE-2008-2398.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2008/CVE-2008-2398.yaml
Copy

References:

https://exchange.xforce.ibmcloud.com/vulnerabilities/42546
https://nvd.nist.gov/vuln/detail/CVE-2008-2398
http://securityreason.com/securityalert/3896