CVE-2009-4994: XSS
Published Aug 25, 2010
·Updated
Cross-site scripting (XSS) vulnerability in frmKBSearch.aspx in SmarterTools SmarterTrack before 4.0.3504 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
Affected Software
22 affected components
SmarterTools SmarterTrack<=4.0.3483
SmarterTools SmarterTrack=3.0.3040
SmarterTools SmarterTrack=3.1.3050
SmarterTools SmarterTrack=3.1.3089
SmarterTools SmarterTrack=3.5.3126
SmarterTools SmarterTrack=3.5.3159
SmarterTools SmarterTrack=3.5.3167
SmarterTools SmarterTrack=3.6.3216
SmarterTools SmarterTrack=3.6.3217
SmarterTools SmarterTrack=3.6.3229
SmarterTools SmarterTrack=3.6.3246
SmarterTools SmarterTrack=3.6.3267
SmarterTools SmarterTrack=3.6.3274
SmarterTools SmarterTrack=3.6.3309
SmarterTools SmarterTrack=3.6.3355
SmarterTools SmarterTrack=3.6.3411
SmarterTools SmarterTrack=3.6.3413
SmarterTools SmarterTrack=4.0.3387
SmarterTools SmarterTrack=4.0.3399
SmarterTools SmarterTrack=4.0.3411
SmarterTools SmarterTrack=4.0.3413
SmarterTools SmarterTrack=4.0.3435
Remediation
Patch Available
Event History
Aug 25, 2010
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-4994?
CVE-2009-4994 is categorized as a high severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2009-4994?
To fix CVE-2009-4994, upgrade SmarterTrack to version 4.0.3504 or later.
3
What type of vulnerability is CVE-2009-4994?
CVE-2009-4994 is a cross-site scripting (XSS) vulnerability.
4
Which versions of SmarterTrack are affected by CVE-2009-4994?
CVE-2009-4994 affects SmarterTrack versions before 4.0.3504, including multiple versions in the 3.x and 4.x series.
5
Can CVE-2009-4994 be exploited remotely?
Yes, CVE-2009-4994 can be exploited remotely by attackers to inject arbitrary web scripts or HTML.