CVE-2009-4782

Theeta CMS - Cross-Site Scripting via Multiple Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-4782.

AI-analyzed exploit summary This is a technical writeup detailing multiple vulnerabilities (XSS and SQL injection) in Theeta CMS. It provides affected URLs, example payloads, and mitigation strategies without functional exploit code.

Description

Multiple cross-site scripting (XSS) vulnerabilities in Theeta CMS, possibly 0.01, allow remote attackers to inject arbitrary web script or HTML via the (1) start, (2) forum, and (3) cat parameters to community/thread.php; (4) start and (5) cat parameters to community/forum.php; and (6) start parameter to blog/index.php.

Exploits (1)

exploitdb WRITEUP
webappsphp
https://www.exploit-db.com/exploits/10290

This is a technical writeup detailing multiple vulnerabilities (XSS and SQL injection) in Theeta CMS. It provides affected URLs, example payloads, and mitigation strategies without functional exploit code.

Classification
Writeup 90%
Attack Type
Xss | Sqli
Complexity
Trivial
Reliability
Theoretical
Target: Theeta CMS
No auth needed
Prerequisites: access to vulnerable Theeta CMS instance
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/508148/100/0/threaded
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/37529

Scores

EPSS 0.0119
EPSS Percentile 79.1%

Details

CWE
CWE-79
Status published
Products (2)
mntechsolutions/theeta_cms 0.0
mntechsolutions/theeta_cms 0.01
Published Apr 21, 2010
Tracked Since Feb 18, 2026