CVE-2009-1458
Razorcms < 0.3 - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in razorCMS before 0.4 allow remote attackers to inject arbitrary web script or HTML via (1) the slab parameter in an edit action, (2) the catname parameter in a showcats action, and (3) the cat parameter in a reordercat action.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Jeremi Gosney · textwebappsphp
https://www.exploit-db.com/exploits/32924
References (7)
Scores
EPSS
0.0227
EPSS Percentile
84.4%
Classification
CWE
CWE-79
Status
published
Affected Products (3)
razorcms/razorcms
< 0.3
razorcms/razorcms
n/a/n/a
Timeline
Published
Apr 28, 2009
Tracked Since
Feb 18, 2026