Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2009-1937
Description:Cross-site scripting (XSS) vulnerability in the comment posting feature in LightNEasy 2.2.1 "no database" (aka flat) and 2.2.2 SQLite allows remote attackers to inject arbitrary web script or HTML via the (1) commentname (aka Author), (2) commentemail (aka Email), and (3) commentmessage (aka Comment) parameters. NOTE: some of these details are obtained from third party information.
Test IDs: 1.3.6.1.4.1.25623.1.0.900372  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2009-1937
BugTraq ID: 35229
http://www.securityfocus.com/bid/35229
Bugtraq: 20090603 [InterN0T] LightNEasy 2.2.2 - HTML Injection Vulnerability (Google Search)
http://www.securityfocus.com/archive/1/504092/100/0/threaded
http://forum.intern0t.net/intern0t-advisories/1081-intern0t-lightneasy-2-2-2-html-injection-vulnerability.html
http://secunia.com/advisories/35354




© 1998-2025 E-Soft Inc. All rights reserved.