CVE-2009-4994
 
Severity Score
6.1
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Cross-site scripting (XSS) vulnerability in frmKBSearch.aspx in SmarterTools SmarterTrack before 4.0.3504 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en frmKBSearch.aspx en SmarterTools, SmarterTrack anterior a v4.0.3504 permite a atacantes remotos inyectar código web o HTML a través del parámetro de búsqueda.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2010-08-25 CVE Reserved
- 2010-08-25 CVE Published
- 2024-09-16 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://holisticinfosec.org/content/view/123/45 | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.smartertools.com/SmarterTrack/ReleaseNotes.aspx | 2010-08-26 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/36172 | 2010-08-26 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Smartertools Search vendor "Smartertools" | Smartertrack Search vendor "Smartertools" for product "Smartertrack" | <= 4.0.3483 Search vendor "Smartertools" for product "Smartertrack" and version " <= 4.0.3483" | - |
Affected
| ||||||
Smartertools Search vendor "Smartertools" | Smartertrack Search vendor "Smartertools" for product "Smartertrack" | 3.0.3040 Search vendor "Smartertools" for product "Smartertrack" and version "3.0.3040" | - |
Affected
| ||||||
Smartertools Search vendor "Smartertools" | Smartertrack Search vendor "Smartertools" for product "Smartertrack" | 3.1.3050 Search vendor "Smartertools" for product "Smartertrack" and version "3.1.3050" | - |
Affected
| ||||||
Smartertools Search vendor "Smartertools" | Smartertrack Search vendor "Smartertools" for product "Smartertrack" | 3.1.3089 Search vendor "Smartertools" for product "Smartertrack" and version "3.1.3089" | - |
Affected
| ||||||
Smartertools Search vendor "Smartertools" | Smartertrack Search vendor "Smartertools" for product "Smartertrack" | 3.5.3126 Search vendor "Smartertools" for product "Smartertrack" and version "3.5.3126" | - |
Affected
| ||||||
Smartertools Search vendor "Smartertools" | Smartertrack Search vendor "Smartertools" for product "Smartertrack" | 3.5.3159 Search vendor "Smartertools" for product "Smartertrack" and version "3.5.3159" | - |
Affected
| ||||||
Smartertools Search vendor "Smartertools" | Smartertrack Search vendor "Smartertools" for product "Smartertrack" | 3.5.3167 Search vendor "Smartertools" for product "Smartertrack" and version "3.5.3167" | - |
Affected
| ||||||
Smartertools Search vendor "Smartertools" | Smartertrack Search vendor "Smartertools" for product "Smartertrack" | 3.6.3216 Search vendor "Smartertools" for product "Smartertrack" and version "3.6.3216" | - |
Affected
| ||||||
Smartertools Search vendor "Smartertools" | Smartertrack Search vendor "Smartertools" for product "Smartertrack" | 3.6.3217 Search vendor "Smartertools" for product "Smartertrack" and version "3.6.3217" | - |
Affected
| ||||||
Smartertools Search vendor "Smartertools" | Smartertrack Search vendor "Smartertools" for product "Smartertrack" | 3.6.3229 Search vendor "Smartertools" for product "Smartertrack" and version "3.6.3229" | - |
Affected
| ||||||
Smartertools Search vendor "Smartertools" | Smartertrack Search vendor "Smartertools" for product "Smartertrack" | 3.6.3246 Search vendor "Smartertools" for product "Smartertrack" and version "3.6.3246" | - |
Affected
| ||||||
Smartertools Search vendor "Smartertools" | Smartertrack Search vendor "Smartertools" for product "Smartertrack" | 3.6.3267 Search vendor "Smartertools" for product "Smartertrack" and version "3.6.3267" | - |
Affected
| ||||||
Smartertools Search vendor "Smartertools" | Smartertrack Search vendor "Smartertools" for product "Smartertrack" | 3.6.3274 Search vendor "Smartertools" for product "Smartertrack" and version "3.6.3274" | - |
Affected
| ||||||
Smartertools Search vendor "Smartertools" | Smartertrack Search vendor "Smartertools" for product "Smartertrack" | 3.6.3309 Search vendor "Smartertools" for product "Smartertrack" and version "3.6.3309" | - |
Affected
| ||||||
Smartertools Search vendor "Smartertools" | Smartertrack Search vendor "Smartertools" for product "Smartertrack" | 3.6.3355 Search vendor "Smartertools" for product "Smartertrack" and version "3.6.3355" | - |
Affected
| ||||||
Smartertools Search vendor "Smartertools" | Smartertrack Search vendor "Smartertools" for product "Smartertrack" | 3.6.3411 Search vendor "Smartertools" for product "Smartertrack" and version "3.6.3411" | - |
Affected
| ||||||
Smartertools Search vendor "Smartertools" | Smartertrack Search vendor "Smartertools" for product "Smartertrack" | 3.6.3413 Search vendor "Smartertools" for product "Smartertrack" and version "3.6.3413" | - |
Affected
| ||||||
Smartertools Search vendor "Smartertools" | Smartertrack Search vendor "Smartertools" for product "Smartertrack" | 4.0.3387 Search vendor "Smartertools" for product "Smartertrack" and version "4.0.3387" | - |
Affected
| ||||||
Smartertools Search vendor "Smartertools" | Smartertrack Search vendor "Smartertools" for product "Smartertrack" | 4.0.3399 Search vendor "Smartertools" for product "Smartertrack" and version "4.0.3399" | - |
Affected
| ||||||
Smartertools Search vendor "Smartertools" | Smartertrack Search vendor "Smartertools" for product "Smartertrack" | 4.0.3411 Search vendor "Smartertools" for product "Smartertrack" and version "4.0.3411" | - |
Affected
| ||||||
Smartertools Search vendor "Smartertools" | Smartertrack Search vendor "Smartertools" for product "Smartertrack" | 4.0.3413 Search vendor "Smartertools" for product "Smartertrack" and version "4.0.3413" | - |
Affected
| ||||||
Smartertools Search vendor "Smartertools" | Smartertrack Search vendor "Smartertools" for product "Smartertrack" | 4.0.3435 Search vendor "Smartertools" for product "Smartertrack" and version "4.0.3435" | - |
Affected
|