CVE-2009-4548
ViArt Helpdesk - 'article.php?category_id' Cross-Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
7Exploited in Wild
-Decision
Descriptions
Multiple cross-site scripting (XSS) vulnerabilities in ViArt Helpdesk 3.x allow remote attackers to inject arbitrary web script or HTML via the category_id parameter to (1) products.php, (2) article.php, (3) product_details.php, or (4) reviews.php; the (5) forum_id parameter to forum.php; or the (6) search_category_id parameter to products_search.php.
Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en ViArt Helpdesk v3.x permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de el parámetro category_id a (1) products.php, (2) article.php, (3) product_details.php, o (4) reviews.php; the (5) el parámetro forum_id a forum.php; o (6) el parámetro search_category_id a products_search.php.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-08-10 First Exploit
- 2010-01-04 CVE Reserved
- 2010-01-04 CVE Published
- 2024-04-08 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (15)
URL | Tag | Source |
---|---|---|
http://osvdb.org/56877 | Vdb Entry | |
http://osvdb.org/56878 | Vdb Entry | |
http://osvdb.org/56879 | Vdb Entry | |
http://osvdb.org/56880 | Vdb Entry | |
http://osvdb.org/56881 | Vdb Entry | |
http://osvdb.org/56882 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/52349 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/34495 | 2009-08-10 | |
https://www.exploit-db.com/exploits/34499 | 2009-08-10 | |
https://www.exploit-db.com/exploits/34498 | 2009-08-10 | |
https://www.exploit-db.com/exploits/34494 | 2009-08-10 | |
https://www.exploit-db.com/exploits/34496 | 2009-08-10 | |
https://www.exploit-db.com/exploits/34497 | 2009-08-10 | |
http://packetstormsecurity.org/0908-exploits/viarthd-xss.txt | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/36240 | 2017-08-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Viart Search vendor "Viart" | Viart Helpdesk Search vendor "Viart" for product "Viart Helpdesk" | 3.3.2 Search vendor "Viart" for product "Viart Helpdesk" and version "3.3.2" | - |
Affected
| ||||||
Viart Search vendor "Viart" | Viart Helpdesk Search vendor "Viart" for product "Viart Helpdesk" | 3.4.7 Search vendor "Viart" for product "Viart Helpdesk" and version "3.4.7" | - |
Affected
|