CVE-2009-4994: XSS

Published Aug 25, 2010
·
Updated

Cross-site scripting (XSS) vulnerability in frmKBSearch.aspx in SmarterTools SmarterTrack before 4.0.3504 allows remote attackers to inject arbitrary web script or HTML via the search parameter.

Affected Software

22 affected components
SmarterTools SmarterTrack<=4.0.3483
SmarterTools SmarterTrack=3.0.3040
SmarterTools SmarterTrack=3.1.3050
SmarterTools SmarterTrack=3.1.3089
SmarterTools SmarterTrack=3.5.3126
SmarterTools SmarterTrack=3.5.3159
SmarterTools SmarterTrack=3.5.3167
SmarterTools SmarterTrack=3.6.3216
SmarterTools SmarterTrack=3.6.3217
SmarterTools SmarterTrack=3.6.3229
SmarterTools SmarterTrack=3.6.3246
SmarterTools SmarterTrack=3.6.3267
SmarterTools SmarterTrack=3.6.3274
SmarterTools SmarterTrack=3.6.3309
SmarterTools SmarterTrack=3.6.3355
SmarterTools SmarterTrack=3.6.3411
SmarterTools SmarterTrack=3.6.3413
SmarterTools SmarterTrack=4.0.3387
SmarterTools SmarterTrack=4.0.3399
SmarterTools SmarterTrack=4.0.3411
SmarterTools SmarterTrack=4.0.3413
SmarterTools SmarterTrack=4.0.3435

Event History

Aug 25, 2010
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2009-4994?

CVE-2009-4994 is categorized as a high severity vulnerability due to its potential for cross-site scripting attacks.

2

How do I fix CVE-2009-4994?

To fix CVE-2009-4994, upgrade SmarterTrack to version 4.0.3504 or later.

3

What type of vulnerability is CVE-2009-4994?

CVE-2009-4994 is a cross-site scripting (XSS) vulnerability.

4

Which versions of SmarterTrack are affected by CVE-2009-4994?

CVE-2009-4994 affects SmarterTrack versions before 4.0.3504, including multiple versions in the 3.x and 4.x series.

5

Can CVE-2009-4994 be exploited remotely?

Yes, CVE-2009-4994 can be exploited remotely by attackers to inject arbitrary web scripts or HTML.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203