CVE-2008-7271 describes multiple cross-site scripting (XSS) vulnerabilities in the Help Contents web application of Eclipse IDE, specifically affecting versions possibly including 3.3.2. Attackers can inject arbitrary web script or HTML via the searchWord parameter in searchView.jsp or the workingSet parameter in workingSetManager.jsp. This vulnerability has a CVSS score of 4.3 (Medium), indicating a network-based attack with medium complexity, requiring no authentication, and resulting in partial integrity impact. While there is no evidence of active exploitation or Metasploit/Nuclei modules, exploit code is publicly available on ExploitDB, though community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:eclipse:eclipse_ide:*:*:*:*:*:*:*:* | ||
3.3.2CPE matchmatch criteria | cpe:2.3:a:eclipse:eclipse_ide:3.3.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.