CVE Vulnerabilities

CVE-2008-5185

Published: Nov 21, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The highlighting functionality in geshi.php in GeSHi before 1.0.8 allows remote attackers to cause a denial of service (infinite loop) via an XML sequence containing an opening delimiter without a closing delimiter, as demonstrated using <.

Affected Software

NameVendorStart VersionEnd Version
GeshiGeshi*1.0.7.22 (including)
GeshiGeshi1.0.0 (including)1.0.0 (including)
GeshiGeshi1.0.1 (including)1.0.1 (including)
GeshiGeshi1.0.2 (including)1.0.2 (including)
GeshiGeshi1.0.2_beta_1 (including)1.0.2_beta_1 (including)
GeshiGeshi1.0.3 (including)1.0.3 (including)
GeshiGeshi1.0.4 (including)1.0.4 (including)
GeshiGeshi1.0.5 (including)1.0.5 (including)
GeshiGeshi1.0.6 (including)1.0.6 (including)
GeshiGeshi1.0.7 (including)1.0.7 (including)
GeshiGeshi1.0.7.1 (including)1.0.7.1 (including)
GeshiGeshi1.0.7.2 (including)1.0.7.2 (including)
GeshiGeshi1.0.7.3 (including)1.0.7.3 (including)
GeshiGeshi1.0.7.4 (including)1.0.7.4 (including)
GeshiGeshi1.0.7.5 (including)1.0.7.5 (including)
GeshiGeshi1.0.7.6 (including)1.0.7.6 (including)
GeshiGeshi1.0.7.7 (including)1.0.7.7 (including)
GeshiGeshi1.0.7.8 (including)1.0.7.8 (including)
GeshiGeshi1.0.7.9 (including)1.0.7.9 (including)
GeshiGeshi1.0.7.10 (including)1.0.7.10 (including)
GeshiGeshi1.0.7.11 (including)1.0.7.11 (including)
GeshiGeshi1.0.7.12 (including)1.0.7.12 (including)
GeshiGeshi1.0.7.13 (including)1.0.7.13 (including)
GeshiGeshi1.0.7.14 (including)1.0.7.14 (including)
GeshiGeshi1.0.7.15 (including)1.0.7.15 (including)
GeshiGeshi1.0.7.16 (including)1.0.7.16 (including)
GeshiGeshi1.0.7.17 (including)1.0.7.17 (including)
GeshiGeshi1.0.7.18 (including)1.0.7.18 (including)
GeshiGeshi1.0.7.19 (including)1.0.7.19 (including)
GeshiGeshi1.0.7.20 (including)1.0.7.20 (including)
GeshiGeshi1.0.7.21 (including)1.0.7.21 (including)
GeshiUbuntugutsy*
GeshiUbuntuhardy*
GeshiUbuntuintrepid*
GeshiUbuntuupstream*

References