CVE-2009-4926
Multiple cross-site scripting (XSS) vulnerabilities in Online Contact Manager (formerly EContact PRO) 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) showGroup parameter to (a) index.php and the (2) id parameter to (b)…
Does this matter?
Lower severity and a low EPSS score (1.64%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Online Contact Manager (formerly EContact PRO) 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) showGroup parameter to (a) index.php and the (2) id parameter to (b) view.php, (c) email.php, (d) edit.php, and (e) delete.php.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.64% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- esoftpro/online contact manager
- Source
- cve@mitre.org
References
- http://packetstorm.linuxsecurity.com/0904-exploits/ocm30-xss.txtExploit
- http://secunia.com/advisories/34826Vendor Advisory
- http://www.securityfocus.com/bid/34626Exploit
- http://packetstorm.linuxsecurity.com/0904-exploits/ocm30-xss.txtExploit
- http://secunia.com/advisories/34826Vendor Advisory
- http://www.securityfocus.com/bid/34626Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.