Unrated severityNVD Advisory· Published Jul 29, 2008· Updated Apr 23, 2026
CVE-2008-3100
CVE-2008-3100
Description
Cross-site scripting (XSS) vulnerability in lib/owl.lib.php in Steve Bourgeois and Chris Vincent Owl Intranet Knowledgebase 0.95 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter in a getpasswd action to register.php.
Affected products
2cpe:2.3:a:owl:intranet_knowledgebase:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:owl:intranet_knowledgebase:*:*:*:*:*:*:*:*range: <=0.95
- cpe:2.3:a:owl:intranet_knowledgebase:0.94:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- www.datensalat.eu/~fabian/cve/CVE-2008-3100-Owl.htmlnvdExploitPatch
- www.securityfocus.com/bid/30410nvdExploitPatch
- secunia.com/advisories/31264nvd
- securityreason.com/securityalert/4057nvd
- www.securityfocus.com/archive/1/494843/100/0/threadednvd
- www.vupen.com/english/advisories/2008/2209nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/44053nvd
News mentions
0No linked articles in our index yet.