VYPR
Unrated severityNVD Advisory· Published May 9, 2008· Updated Apr 23, 2026

CVE-2008-2133

CVE-2008-2133

Description

Cross-site scripting (XSS) vulnerability in the Journal module in Tru-Zone Nuke ET 3.x allows remote attackers to inject arbitrary web script or HTML via the title parameter in a new entry, as demonstrated by a CSS property in the STYLE attribute of a DIV element, a different vulnerability than CVE-2008-1873.

Affected products

6
  • Tru Zone/Nukeet6 versions
    cpe:2.3:a:tru-zone:nukeet:3.0:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:tru-zone:nukeet:3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:tru-zone:nukeet:3.1:*:*:*:*:*:*:*
    • cpe:2.3:a:tru-zone:nukeet:3.2:*:*:*:*:*:*:*
    • cpe:2.3:a:tru-zone:nukeet:3.3:*:*:*:*:*:*:*
    • cpe:2.3:a:tru-zone:nukeet:3.4:*:*:*:*:*:*:*
    • cpe:2.3:a:tru-zone:nukeet:3.9:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.