CVE-2009-1408
Cross-site scripting (XSS) vulnerability in webSPELL 4.2.0c allows remote attackers to inject arbitrary web script or HTML allows remote attackers to inject arbitrary web script or HTML via Javascript events such as onmouseover in nested BBcode tags, as…
Does this matter?
Lower severity and a low EPSS score (2.02%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in webSPELL 4.2.0c allows remote attackers to inject arbitrary web script or HTML allows remote attackers to inject arbitrary web script or HTML via Javascript events such as onmouseover in nested BBcode tags, as demonstrated using (1) email, (2) img, and (3) url tags.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 2.02% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- webspell/webspell
- Source
- cve@mitre.org
References
- http://osvdb.org/53782
- http://secunia.com/advisories/34764Vendor Advisory
- http://www.securityfocus.com/archive/1/502732/100/0/threaded
- http://www.securityfocus.com/bid/34595Exploit, Patch
- http://www.webspell.org/index.php?site=files&file=25Patch, Vendor Advisory
- http://www.webspell.org/index.php?site=news_comments&newsID=126&lang=ukPatch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49937
- https://www.exploit-db.com/exploits/8453
- http://osvdb.org/53782
- http://secunia.com/advisories/34764Vendor Advisory
- http://www.securityfocus.com/archive/1/502732/100/0/threaded
- http://www.securityfocus.com/bid/34595Exploit, Patch
- http://www.webspell.org/index.php?site=files&file=25Patch, Vendor Advisory
- http://www.webspell.org/index.php?site=news_comments&newsID=126&lang=ukPatch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49937
- https://www.exploit-db.com/exploits/8453
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.