VulnerabilityModified
CVE-2009-0303
Cross-site scripting (XSS) vulnerability in Web Help Desk before 9.1.18 allows remote attackers to inject arbitrary web script or HTML via vectors related to "encoded JavaScript" and Helpdesk.woa.
MEDIUM 4.3EPSS 1.02%
Does this matter?
Lower severity and a low EPSS score (1.02%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in Web Help Desk before 9.1.18 allows remote attackers to inject arbitrary web script or HTML via vectors related to "encoded JavaScript" and Helpdesk.woa.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.02% probability · 62th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- webhelpdesk/web help desk
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/33651Vendor Advisory
- http://updates.webhelpdesk.com/weblog/updates/StableReleases/2009/01/23/911812309.htmlVendor Advisory
- http://www.securityfocus.com/bid/33429
- http://secunia.com/advisories/33651Vendor Advisory
- http://updates.webhelpdesk.com/weblog/updates/StableReleases/2009/01/23/911812309.htmlVendor Advisory
- http://www.securityfocus.com/bid/33429
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.