VulnerabilityModified
CVE-2009-2785
Multiple cross-site scripting (XSS) vulnerabilities in PHP Open Classifieds Script allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter to buy.php and the id parameter to (2) contact.php and (3) tellafriend.php.
MEDIUM 4.3EPSS 1.30%
Does this matter?
Lower severity and a low EPSS score (1.30%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in PHP Open Classifieds Script allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter to buy.php and the id parameter to (2) contact.php and (3) tellafriend.php.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.30% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- classifiedphpscript/php open classifieds script
- Source
- cve@mitre.org
References
- http://osvdb.org/56657Exploit
- http://osvdb.org/56658Exploit
- http://osvdb.org/56659Exploit
- http://packetstormsecurity.org/0907-exploits/openclassifieds-xss.txt
- http://secunia.com/advisories/35929Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/52123
- http://osvdb.org/56657Exploit
- http://osvdb.org/56658Exploit
- http://osvdb.org/56659Exploit
- http://packetstormsecurity.org/0907-exploits/openclassifieds-xss.txt
- http://secunia.com/advisories/35929Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/52123
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.