Tracker / CVE-2009-4040
CVE-2009-4040
Medium 4.3
Cross-site scripting (XSS) vulnerability in phpMyFAQ before 2.0.17 and 2.5.x before 2.5.2, when used with Internet Explorer 6 or 7, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to the search page.
Affected products and versions
| phpmyfaq | phpmyfaq |
|---|---|
| phpmyfaq | phpmyfaq · … → 2.0.16 |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.