First published: Sun Dec 20 2009(Updated: )
Cross-site scripting (XSS) vulnerability in folder.php in the SmartMedia 0.85 Beta module for XOOPS allows remote attackers to inject arbitrary web script or HTML via the categoryid parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Smartmedia | =0.85-beta | |
Xoops |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4359 has been classified with a moderate severity due to its cross-site scripting (XSS) vulnerability.
To fix CVE-2009-4359, ensure that user inputs, specifically the categoryid parameter, are properly sanitized and validated.
CVE-2009-4359 affects users of the SmartMedia 0.85 Beta module for XOOPS due to its XSS vulnerability.
An attacker can perform a cross-site scripting (XSS) attack using CVE-2009-4359 by injecting arbitrary web scripts into the application.
While CVE-2009-4359 is an older vulnerability, it remains relevant for those using affected versions of the SmartMedia module.