First published: Fri Sep 18 2009(Updated: )
Cross-site scripting (XSS) vulnerability in the Happy Linux XF-Section module 1.12a for XOOPS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ohwada Xf-section | =1.12a | |
Xoops Xm Memberstats |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-3240 has a medium severity level due to its ability to enable cross-site scripting attacks.
To fix CVE-2009-3240, upgrade the Happy Linux XF-Section module to a version that is not vulnerable.
CVE-2009-3240 specifically affects version 1.12a of the Happy Linux XF-Section module.
Yes, CVE-2009-3240 can be exploited remotely by attackers through the injection of malicious scripts.
Implementing input validation and sanitization can help prevent exploitation of CVE-2009-3240.