CVE-2009-2107

Webmedia Explorer 5.09-5.10 - XSS

Title source: llm
STIX 2.1

Description

Multiple cross-site scripting (XSS) vulnerabilities in index.php in Webmedia Explorer (webmex) 5.09 and 5.10 allow remote attackers to inject arbitrary web script or HTML via event handlers such as onmouseover in the (1) search or (2) tag parameters; (3) arbitrary invalid parameter names that are not properly handled when triggered on a column; (4) bookmark parameter in an edit action; or (5) email parameter in a remember action.

Exploits (1)

exploitdb WORKING POC VERIFIED
by intern0t · textwebappsphp
https://www.exploit-db.com/exploits/33038

References (4)

Core 4
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/35368
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/504307/100/0/threaded
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35477

Scores

EPSS 0.0096
EPSS Percentile 76.6%

Details

CWE
CWE-79
Status published
Products (2)
webmediaexplorer/webmedia_explorer 5.09
webmediaexplorer/webmedia_explorer 5.10
Published Jun 17, 2009
Tracked Since Feb 18, 2026