Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2009-2783

Overview

Vulnerability Score 4.3 4.3
CVE Id CVE-2009-2783
Last Modified 14 Aug 2013 02:04:09
Published 17 Aug 2009 12:30:01
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2009-2783

Summary

Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.3.3 allow remote attackers to inject arbitrary web script or HTML via the (1) op parameter to modules/pm/viewpmsg.php and (2) query string to modules/profile/user.php.

Vulnerable Systems

Application

  • Xoops 2.3.3


References

CONFIRM - http://xoops.svn.sourceforge.net/viewvc/xoops/XoopsCore/trunk/htdocs/modules/pm/viewpmsg.php?r1=2621&r2=3292

CONFIRM - http://xoops.svn.sourceforge.net/viewvc/xoops/XoopsCore/trunk/htdocs/modules/pm/viewpmsg.php?view=log#rev3292

MISC - http://www.senseofsecurity.com.au/advisories/SOS-09-005.pdf

SECTRACK - 1022641

BID - 35895

SECUNIA - 36109

OSVDB - 56638

BUGTRAQ - 20090731 XOOPS Multiple Cross-Site Scripting Vulnerabilities - Security Advisory - SOS-09-005


Last Updated: 27 May 2016 10:51:01