CVE-2008-5225

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
25/11/2008
Last modified:
09/04/2025

Description

Multiple cross-site scripting (XSS) vulnerabilities in Xerox DocuShare 6 and earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) SearchResults/ and (2) Services/ in dsdn/dsweb/, and (3) the default URI under unspecified docushare/dsweb/ServicesLib/Group-#/ directories.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:xerox:docushare:*:*:*:*:*:*:*:* 6 (including)
cpe:2.3:a:xerox:docushare:4:*:*:*:*:*:*:*
cpe:2.3:a:xerox:docushare:5:*:*:*:*:*:*:*
cpe:2.3:a:xerox:docushare:5.00.00.2:*:*:*:*:*:*:*
cpe:2.3:a:xerox:docushare:6.0:*:*:*:*:*:*:*
cpe:2.3:a:xerox:docushare:6.00.00.1:*:*:*:*:*:*:*
cpe:2.3:a:xerox:docushare:6.0.1:*:*:*:*:*:*:*