First published: Thu Jul 22 2010(Updated: )
Cross-site scripting (XSS) vulnerability in the Visitor Tracking (ws_stats) extension before 0.1.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
wapplersystems ws stats | <=0.1.1 | |
wapplersystems ws stats | =0.0.13 | |
wapplersystems ws stats | =0.0.15 | |
wapplersystems ws stats | =0.1.0 | |
TYPO3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4956 is classified as a medium-severity cross-site scripting vulnerability.
To fix CVE-2009-4956, upgrade the Visitor Tracking (ws_stats) extension to version 0.1.2 or later.
CVE-2009-4956 affects versions of the Visitor Tracking (ws_stats) extension prior to 0.1.2.
CVE-2009-4956 is a cross-site scripting (XSS) vulnerability.
Attackers can inject arbitrary web scripts or HTML through CVE-2009-4956.