4.3
CVSSv2

CVE-2009-2145

Published: 22/06/2009 Updated: 29/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in transLucid 1.75 allow remote malicious users to inject arbitrary web script or HTML via the (a) NodeID and (b) action parameters to the default URI, and the (c) NodeID parameter to the default URI for the admin section; and allow remote authenticated users to inject arbitrary web script or HTML via the (d) Title (aka page name) and (e) Url fields in a (1) new or (2) modified page.

Vulnerable Product Search on Vulmon Subscribe to Product

pantha translucid 1.75

Exploits

transLucid - Cross Site Scripting and HTML Injection Vulnerabilities Version Affected: 175 (newest) Info: transLucidonline is the easy website publishing system with which anyone can create and maintain web content, in multiple languages and based on a growing list of ready-made, professional layouts Credits: InterN0T (macd3v and MaXe) Extern ...