CVE-2009-4984

Websitesrus Accessories ME Php Affiliate Script - XSS

Title source: rule
STIX 2.1

Description

Multiple cross-site scripting (XSS) vulnerabilities in Accessories Me PHP Affiliate Script 1.4 allow remote attackers to inject arbitrary web script or HTML via the (1) Keywords parameter to search.php and (2) SearchIndex parameter to browse.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Moudi · textwebappsphp
https://www.exploit-db.com/exploits/9370

References (2)

Core 2
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/9370
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/36148

Scores

EPSS 0.0051
EPSS Percentile 66.6%

Details

CWE
CWE-79
Status published
Products (1)
websitesrus/accessories_me_php_affiliate_script 1.4
Published Aug 25, 2010
Tracked Since Feb 18, 2026