First published: Wed Sep 16 2009(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in AlmondSoft Almond Classifieds Wap and Pro, and possibly Almond Affiliate Network Classifieds, allow remote attackers to inject arbitrary web script or HTML via (1) the page parameter in a browse action to index.php or (2) the addr parameter to gmap.php. NOTE: some of these details are obtained from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Almondsoft Affiliate Network Classifieds | ||
Almondsoft Affiliate Network Classifieds |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-3225 is classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2009-3225, ensure that input from the page and addr parameters is properly sanitized and validated to prevent script injection.
CVE-2009-3225 affects multiple versions of AlmondSoft Almond Classifieds Wap and Pro, as well as potentially Almond Affiliate Network Classifieds.
Exploiting CVE-2009-3225 can allow remote attackers to execute arbitrary web scripts or HTML in the context of a user's session.
Yes, there are various reported exploits for CVE-2009-3225 that demonstrate how to leverage the cross-site scripting vulnerabilities.