CVE-2009-4814

Wolfram webMathematica - Cross-Site Scripting via URI to MSP Script

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-4814. PoCs published by Floyd Fuh.

AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in webMathematica due to insufficient input sanitization. It includes a proof-of-concept URL demonstrating the issue but lacks executable exploit code.

Description

Cross-site scripting (XSS) vulnerability in Wolfram Research webMathematica allows remote attackers to inject arbitrary web script or HTML via the URI to the MSP script.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Floyd Fuh · textwebappsmultiple
https://www.exploit-db.com/exploits/33438

The provided text describes a cross-site scripting (XSS) vulnerability in webMathematica due to insufficient input sanitization. It includes a proof-of-concept URL demonstrating the issue but lacks executable exploit code.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: webMathematica (version not specified)
No auth needed
Prerequisites: Access to a vulnerable webMathematica instance
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Exploit vdb-entry x_refsource_osvdb
http://osvdb.org/61266
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/37905
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/37451
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/55008

Scores

EPSS 0.0199
EPSS Percentile 83.8%

Details

CWE
CWE-79
Status published
Products (3)
wolfram/webmathematica
wolfram/webmathematica 2.3
wolfram/webmathematica 3.0
Published Apr 27, 2010
Tracked Since Feb 18, 2026