Multiple cross-site scripting (XSS) vulnerabilities in index.php in Webmedia Explorer (webmex) 5.09 and 5.10 allow remote attackers to inject arbitrary web script or HTML via event handlers such as onmouseover in the (1) search or (2) tag parameters; (3) arbitrary invalid parameter names that are not properly handled when triggered on a column; (4) bookmark parameter in an edit action; or (5) email parameter in a remember action.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2009-06-17T17:00:00
Updated: 2024-08-07T05:36:20.962Z
Reserved: 2009-06-17T00:00:00
Link: CVE-2009-2107
Vulnrichment
No data.
NVD
Status : Modified
Published: 2009-06-17T17:30:00.627
Modified: 2024-11-21T01:04:08.667
Link: CVE-2009-2107
Redhat
No data.