CVE-2009-0338: XSS
Published Jan 29, 2009
·Updated
Cross-site scripting (XSS) vulnerability in incwebblogmanager.asp in DMXReady Blog Manager allows remote attackers to inject arbitrary web script or HTML via the CategoryID parameter in a refer action.
Affected Software
1 affected component
DMXReady Blog Manager=_nil
Event History
Jan 29, 2009
CVE Published
via MITRE·06:09 PM
Data Sourced
via MITRE·06:09 PM
Description
Data Sourced
via NVD·06:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-0338?
CVE-2009-0338 is classified as a medium severity vulnerability due to its potential for enabling cross-site scripting attacks.
2
How do I fix CVE-2009-0338?
To fix CVE-2009-0338, validate and sanitize user input to the CategoryID parameter in the inc_webblogmanager.asp file.
3
What systems are affected by CVE-2009-0338?
The affected software for CVE-2009-0338 is DMXReady Blog Manager version _nil.
4
What type of vulnerability is CVE-2009-0338?
CVE-2009-0338 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2009-0338 lead to data theft?
Yes, CVE-2009-0338 can lead to data theft as it allows attackers to inject malicious scripts into web pages, potentially compromising user data.