CVE-2009-4395: XSS
Published Dec 22, 2009
·Updated
Cross-site scripting (XSS) vulnerability in the Random Prayer 2 (steprayer2) extension 0.0.3 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
3 affected components
Fr.simon Rundell Ste Prayer2<=0.0.3
Fr.simon Rundell Ste Prayer2=0.0.2
Typo3 TYPO3
Event History
Dec 22, 2009
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Data Sourced
11:30 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-4395?
CVE-2009-4395 has a moderate severity level due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2009-4395?
To fix CVE-2009-4395, upgrade the Random Prayer 2 extension to version 0.0.4 or later.
3
What versions of Random Prayer 2 are affected by CVE-2009-4395?
CVE-2009-4395 affects version 0.0.3 and earlier of the Random Prayer 2 extension.
4
Can CVE-2009-4395 affect TYPO3 itself?
CVE-2009-4395 specifically affects the Random Prayer 2 extension and does not impact TYPO3 core versions.
5
What type of vulnerability is CVE-2009-4395?
CVE-2009-4395 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject malicious scripts.