First published: Fri Apr 24 2009(Updated: )
Cross-site scripting (XSS) vulnerability in webSPELL 4.2.0c allows remote attackers to inject arbitrary web script or HTML allows remote attackers to inject arbitrary web script or HTML via Javascript events such as onmouseover in nested BBcode tags, as demonstrated using (1) email, (2) img, and (3) url tags.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webspell | =4.2.0c |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-1408 has a medium severity level due to its potential for exploitation via cross-site scripting.
To fix CVE-2009-1408, it is recommended to upgrade to a patched version of webSPELL that removes the vulnerability.
CVE-2009-1408 is classified as a cross-site scripting (XSS) vulnerability.
CVE-2009-1408 affects webSPELL version 4.2.0c.
Yes, CVE-2009-1408 can be exploited remotely by injecting arbitrary web scripts or HTML.