CVE-2009-4403: XSS
Published Dec 23, 2009
·Updated
Cross-site scripting (XSS) vulnerability in index.php in Rumba XML 1.8 allows remote attackers to inject arbitrary web script or HTML via the PATHINFO. NOTE: some of these details are obtained from third party information.
Affected Software
1 affected component
Rumbacms Rumba Xml=1.8
Event History
Dec 23, 2009
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-4403?
CVE-2009-4403 is classified as a medium severity vulnerability due to its cross-site scripting (XSS) nature.
2
How do I fix CVE-2009-4403?
To fix CVE-2009-4403, upgrade to a version of Rumba XML that does not contain this vulnerability, if available.
3
What type of attack does CVE-2009-4403 facilitate?
CVE-2009-4403 facilitates cross-site scripting (XSS) attacks, allowing attackers to inject arbitrary web scripts or HTML.
4
Who is affected by CVE-2009-4403?
Users of Rumba XML version 1.8 are specifically affected by CVE-2009-4403.
5
What components are vulnerable in CVE-2009-4403?
The vulnerability occurs in the index.php file within the Rumba XML 1.8 application.