CVE-2009-4473
Ektron CMS400.NET <7.66sp2 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in WorkArea/ContentDesigner/ekformsiframe.aspx in Ektron CMS400.NET 7.6.1.53 and 7.6.6.47, and possibly 7.52 through 7.66sp2, allow remote attackers to inject arbitrary web script or HTML via the (1) css, (2) eca, (3) id, and (4) skin parameters. NOTE: some of these details are obtained from third party information.
References (6)
Scores
EPSS
0.0078
EPSS Percentile
73.4%
Classification
CWE
CWE-79
Status
published
Affected Products (23)
ektron/cms4000.net
ektron/cms4000.net
ektron/cms4000.net
ektron/cms4000.net
ektron/cms4000.net
ektron/cms4000.net
ektron/cms4000.net
ektron/cms4000.net
ektron/cms4000.net
ektron/cms4000.net
ektron/cms4000.net
ektron/cms4000.net
ektron/cms4000.net
ektron/cms4000.net
ektron/cms4000.net
... and 8 more
Timeline
Published
Dec 30, 2009
Tracked Since
Feb 18, 2026