Multiple cross-site scripting (XSS) vulnerabilities in Xerox DocuShare 6 and earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) SearchResults/ and (2) Services/ in dsdn/dsweb/, and (3) the default URI under unspecified docushare/dsweb/ServicesLib/Group-#/ directories.
2008-11-25T19:30:08.467
2025-04-09T00:30:58.490
Deferred
CVSSv2: 4.3 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | xerox | docushare | ≤ 6 | Yes |
Application | xerox | docushare | 4 | Yes |
Application | xerox | docushare | 5 | Yes |
Application | xerox | docushare | 5.00.00.2 | Yes |
Application | xerox | docushare | 6.0 | Yes |
Application | xerox | docushare | 6.00.00.1 | Yes |
Application | xerox | docushare | 6.0.1 | Yes |