CVE-2009-4713: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Qas (aka Quas) module for XOOPS Celepar allow remote attackers to inject arbitrary web script or HTML via (1) the codcategoria parameter to categoria.php, (2) the opcao parameter to index.php, and the PATHINFO to (3) categoria.php and (4) index.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4713?
CVE-2009-4713 is classified as a medium severity vulnerability due to its impact on user data security through cross-site scripting.
How do I fix CVE-2009-4713?
To fix CVE-2009-4713, you should upgrade to a newer version of the Qas module for XOOPS Celepar that addresses these XSS vulnerabilities.
What software is affected by CVE-2009-4713?
CVE-2009-4713 affects version 1.0.1 of the Qas module for XOOPS Celepar.
What are the main attack vectors for CVE-2009-4713?
The main attack vectors for CVE-2009-4713 include the cod_categoria parameter to categoria.php, the opcao parameter to index.php, and the PATH_INFO to categoria.php.
Can CVE-2009-4713 be exploited remotely?
Yes, CVE-2009-4713 can be exploited remotely by attackers to inject arbitrary web script or HTML.