CVE-2009-1845

Lussumo Vanilla - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in ajax/updatecheck.php in Lussumo Vanilla 1.1.5 and 1.1.7 allows remote attackers to inject arbitrary web script or HTML via the RequestName parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Gerendi Sandor Attila · textwebappsphp
https://www.exploit-db.com/exploits/33013

Scores

EPSS 0.0096
EPSS Percentile 76.2%

Classification

CWE
CWE-79
Status published

Affected Products (3)

lussumo/vanilla
lussumo/vanilla
n/a/n/a

Timeline

Published Jun 01, 2009
Tracked Since Feb 18, 2026