CVE-2009-2107

Webmedia Explorer 5.09-5.10 - Cross-Site Scripting via Event Handlers in Search/Tag Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-2107. PoCs published by intern0t.

AI-analyzed exploit summary This exploit demonstrates multiple XSS vulnerabilities in Webmedia Explorer by injecting malicious JavaScript via URL parameters and POST data. The PoC includes examples of reflected XSS through query strings and form submissions.

Description

Multiple cross-site scripting (XSS) vulnerabilities in index.php in Webmedia Explorer (webmex) 5.09 and 5.10 allow remote attackers to inject arbitrary web script or HTML via event handlers such as onmouseover in the (1) search or (2) tag parameters; (3) arbitrary invalid parameter names that are not properly handled when triggered on a column; (4) bookmark parameter in an edit action; or (5) email parameter in a remember action.

Exploits (1)

exploitdb WORKING POC VERIFIED
by intern0t · textwebappsphp
https://www.exploit-db.com/exploits/33038

This exploit demonstrates multiple XSS vulnerabilities in Webmedia Explorer by injecting malicious JavaScript via URL parameters and POST data. The PoC includes examples of reflected XSS through query strings and form submissions.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Webmedia Explorer 5.0.9, 5.10.0
No auth needed
Prerequisites: Access to the target web application
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/35368
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/504307/100/0/threaded
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35477

Scores

EPSS 0.0145
EPSS Percentile 70.0%

Details

CWE
CWE-79
Status published
Products (2)
webmediaexplorer/webmedia_explorer 5.09
webmediaexplorer/webmedia_explorer 5.10
Published Jun 17, 2009
Tracked Since Feb 18, 2026