CVE-2009-1070
Expressionengine - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in system/index.php in ExpressionEngine 1.6.4 through 1.6.6, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the avatar parameter.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Adam Baldwin · textwebappsphp
https://www.exploit-db.com/exploits/32871
References (6)
Scores
EPSS
0.0197
EPSS Percentile
83.3%
Classification
CWE
CWE-79
Status
published
Affected Products (4)
expressionengine/expressionengine
expressionengine/expressionengine
expressionengine/expressionengine
n/a/n/a
Timeline
Published
Mar 26, 2009
Tracked Since
Feb 18, 2026