Lucene search

K
cveMitreCVE-2009-2780
HistoryAug 17, 2009 - 4:30 p.m.

CVE-2009-2780

2009-08-1716:30:01
CWE-79
mitre
web.nvd.nist.gov
30
68 classifieds
xss vulnerabilities
remote attackers
web script injection
html injection

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.9

Confidence

High

EPSS

0.007

Percentile

79.8%

Multiple cross-site scripting (XSS) vulnerabilities in 68 Classifieds 4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to category.php, view parameter to (2) login.php and (3) viewlisting.php, page parameter to (4) searchresults.php and (5) toplistings.php, and (6) member parameter to viewmember.php.

Affected configurations

Nvd
Node
68_classifieds68_classifiedsMatch4.1
VendorProductVersionCPE
68_classifieds68_classifieds4.1cpe:2.3:a:68_classifieds:68_classifieds:4.1:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.9

Confidence

High

EPSS

0.007

Percentile

79.8%

Related for CVE-2009-2780