CVE-2009-4497
LXR Cross Referencer <0.9.6 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in LXR Cross Referencer 0.9.5 and 0.9.6 allows remote attackers to inject arbitrary web script or HTML via the i parameter to the ident program.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Dan Rosenberg · textwebappsphp
https://www.exploit-db.com/exploits/33469
Scores
EPSS
0.0019
EPSS Percentile
40.9%
Classification
CWE
CWE-79
Status
published
Affected Products (3)
malcom_box/lxr_cross_referencer
malcom_box/lxr_cross_referencer
n/a/n/a
Timeline
Published
Jan 07, 2010
Tracked Since
Feb 18, 2026