First published: Fri Mar 26 2010(Updated: )
Cross-site scripting (XSS) vulnerability in the Contact module in Exponent CMS 0.97-GA20090213 allows remote attackers to inject arbitrary web script or HTML via the email parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oicgroup Exponent Cms | =0.97-ga20090213 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4744 is classified as a moderate severity cross-site scripting vulnerability.
To fix CVE-2009-4744, upgrade Exponent CMS to a newer version that addresses this vulnerability.
CVE-2009-4744 specifically affects Exponent CMS version 0.97-GA20090213.
CVE-2009-4744 is a cross-site scripting (XSS) vulnerability that allows for the injection of arbitrary web scripts or HTML.
Yes, CVE-2009-4744 can be exploited remotely by attackers through the email parameter in the Contact module.