CVE-2009-1937
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Cross-site scripting (XSS) vulnerability in the comment posting feature in LightNEasy 2.2.1 "no database" (aka flat) and 2.2.2 SQLite allows remote attackers to inject arbitrary web script or HTML via the (1) commentname (aka Author), (2) commentemail (aka Email), and (3) commentmessage (aka Comment) parameters. NOTE: some of these details are obtained from third party information.
Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en funcionalidad de realizar comentarios de LightNEasy v2.2.1 "no database" (sin base de datos o "flat") and 2.2.2 SQLite. Permite a usuarios remotos inyectar codigo de script web o código HTML a través de los parámetros (1) "commentname" (autor), (2) "commentemail" (dirección de correo) y (3) "commentmessage" (comentario). NOTA: algunos de estos detalles han sido obtenidos de información proveniente de terceras partes
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-06-05 CVE Reserved
- 2009-06-05 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://forum.intern0t.net/intern0t-advisories/1081-intern0t-lightneasy-2-2-2-html-injection-vulnerability.html | X_refsource_misc | |
http://www.securityfocus.com/archive/1/504092/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/35229 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/35354 | 2018-10-10 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Lightneasy Search vendor "Lightneasy" | Lightneasy Search vendor "Lightneasy" for product "Lightneasy" | 2.2.1 Search vendor "Lightneasy" for product "Lightneasy" and version "2.2.1" | no_database |
Affected
| ||||||
Lightneasy Search vendor "Lightneasy" | Lightneasy Search vendor "Lightneasy" for product "Lightneasy" | 2.2.2 Search vendor "Lightneasy" for product "Lightneasy" and version "2.2.2" | sqlite |
Affected
|