Unrated severityNVD Advisory· Published Feb 19, 2008· Updated Apr 23, 2026
CVE-2008-0820
CVE-2008-0820
Description
Cross-site scripting (XSS) vulnerability in index.php in Etomite 0.6.1.4 Final allows remote attackers to inject arbitrary web script or HTML via $_SERVER['PHP_INFO']. NOTE: the vendor disputes this issue in a followup, stating that the affected variable is $_SERVER['PHP_SELF'], and "This is not an Etomite specific exploit and I would like the report rescinded.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- www.securityfocus.com/bid/27794nvdExploit
- secunia.com/advisories/28964nvdVendor Advisory
- securityreason.com/securityalert/3669nvd
- www.etomite.com/forums/index.phpnvd
- www.securityfocus.com/archive/1/488122/100/0/threadednvd
- www.securityfocus.com/archive/1/488304/100/100/threadednvd
- exchange.xforce.ibmcloud.com/vulnerabilities/40525nvd
News mentions
0No linked articles in our index yet.