CVE Database
/

CVE-2009-4168

Back to search

CVE-2009-4168

Published: Dec 2, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

Cross-site scripting (XSS) vulnerability in Roy Tanck tagcloud.swf, as used in the WP-Cumulus plugin before 1.23 for WordPress and the Joomulus module 2.0 and earlier for Joomla!, allows remote attackers to inject arbitrary web script or HTML via the tagcloud parameter in a tags action. Cross-site scripting (XSS) vulnerability in tagcloud.swf in the WP-Cumulus Plug-in before 1.23 for WordPress allows remote attackers to inject arbitrary web script or HTML via the tagcloud parameter.

VendorProductVersions

n/a

n/a

affected
n/a

References

20091225 Vulnerability in Joomulus for Joomla
mailing-list
x_refsource_BUGTRAQ
joomulus-tagcloud-xss(55156)
vdb-entry
x_refsource_XF
37483
third-party-advisory
x_refsource_SECUNIA
ADV-2009-3322
vdb-entry
x_refsource_VUPEN
38161
third-party-advisory
x_refsource_SECUNIA
37100
vdb-entry
x_refsource_BID
wpcumulus-tagcloud-xss(54397)
vdb-entry
x_refsource_XF
37479
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now