4.3

CVE-2009-4994

Cross-site scripting (XSS) vulnerability in frmKBSearch.aspx in SmarterTools SmarterTrack before 4.0.3504 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SmarterTools ≫ Smartertrack Version <= 4.0.3483
SmarterTools ≫ Smartertrack Version 3.0.3040
SmarterTools ≫ Smartertrack Version 3.1.3050
SmarterTools ≫ Smartertrack Version 3.1.3089
SmarterTools ≫ Smartertrack Version 3.5.3126
SmarterTools ≫ Smartertrack Version 3.5.3159
SmarterTools ≫ Smartertrack Version 3.5.3167
SmarterTools ≫ Smartertrack Version 3.6.3216
SmarterTools ≫ Smartertrack Version 3.6.3217
SmarterTools ≫ Smartertrack Version 3.6.3229
SmarterTools ≫ Smartertrack Version 3.6.3246
SmarterTools ≫ Smartertrack Version 3.6.3267
SmarterTools ≫ Smartertrack Version 3.6.3274
SmarterTools ≫ Smartertrack Version 3.6.3309
SmarterTools ≫ Smartertrack Version 3.6.3355
SmarterTools ≫ Smartertrack Version 3.6.3411
SmarterTools ≫ Smartertrack Version 3.6.3413
SmarterTools ≫ Smartertrack Version 4.0.3387
SmarterTools ≫ Smartertrack Version 4.0.3399
SmarterTools ≫ Smartertrack Version 4.0.3411
SmarterTools ≫ Smartertrack Version 4.0.3413
SmarterTools ≫ Smartertrack Version 4.0.3435
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.02% 0.59
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

http://holisticinfosec.org/content/view/123/45/
http://secunia.com/advisories/36172
Vendor Advisory
http://www.smartertools.com/SmarterTrack/ReleaseNotes.aspx
Patch