CVE-2008-0980

Exp

Multiple cross-site scripting (XSS) vulnerabilities in Spyce - Python Server Pages (PSP) 2.1.3 allow remote attackers to inject arbitrary web script or HTML via (1) the url or type parameter to docs/examples/redirect.spy; (2) the x parameter to docs/examples/handlervalidate.spy; (3) the name parameter to spyce/examples/request.spy; (4) the Name parameter to spyce/examples/getpost.spy; (5) the mytextarea parameter, the mypass parameter, or an empty parameter to spyce/examples/formtag.spy; (6) the newline parameter to the default URI under demos/chat/; (7) the text1 parameter to docs/examples/formintro.spy; or (8) the mytext or mydate parameter to docs/examples/formtag.spy.

Published: 2008-02-25 Last update: 2026-06-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2008-0980 is rated Exploit Available (58/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 1.48%). Core evidence: 7 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +1.15% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2008-0980

EDB-ID Source Kind Published Link
31267 exploit_db edb 2007-02-19 Exploit-DB ↗
31268 exploit_db edb 2007-02-19 Exploit-DB ↗
31266 exploit_db edb 2007-02-19 Exploit-DB ↗
31269 exploit_db edb 2007-02-19 Exploit-DB ↗
31265 exploit_db edb 2007-02-19 Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗
nvd_ref exploit_tag Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2008-0980

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 0.33% 1.48% +1.15%
2 2026-03-19 0.37% 0.33% -0.04%
3 2025-10-21 0.37%

Full EPSS history (12 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2008-0980

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
4.3 2.0 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:N)
No confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:N)
No availability impact.
8.6 2.9 [email protected]

Weakness enumeration for CVE-2008-0980

Affected software / configurations for CVE-2008-0980

Vendor Product Version Raw CPE
spyce spyce 2.1.3 cpe:2.3:a:spyce:spyce:2.1.3:*:*:*:*:*:*:*

References for CVE-2008-0980

cvelogic Threat Intelligence