CVE-2009-0466: XSS
Published Feb 6, 2009
·Updated
Cross-site scripting (XSS) vulnerability in Vivvo CMS before 4.1.1 allows remote attackers to inject arbitrary web script or HTML via a URI that triggers a 404 Page Not Found response.
Affected Software
5 affected components
Vivvo Vivvo=4.0.4
Vivvo Vivvo=4.0.1
Vivvo Vivvo=4.0.3
Vivvo Vivvo<=4.1.0
Vivvo Vivvo=4.0.2
Event History
Feb 6, 2009
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Feb 10, 2009
Data Sourced
via NVD·07:00 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-0466?
CVE-2009-0466 is categorized as a high severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2009-0466?
To fix CVE-2009-0466, upgrade Vivvo CMS to version 4.1.1 or later.
3
What versions of Vivvo CMS are affected by CVE-2009-0466?
Versions 4.0.1 to 4.1.0 of Vivvo CMS are affected by CVE-2009-0466.
4
What type of vulnerability is CVE-2009-0466?
CVE-2009-0466 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2009-0466 be exploited remotely?
Yes, CVE-2009-0466 can be exploited remotely by injecting malicious web scripts via a crafted URI.