Show plain JSON{"containers": {"cna": {"affected": [{"product": "n/a", "vendor": "n/a", "versions": [{"status": "affected", "version": "n/a"}]}], "datePublic": "2009-04-16T00:00:00", "descriptions": [{"lang": "en", "value": "Cross-site scripting (XSS) vulnerability in webSPELL 4.2.0c allows remote attackers to inject arbitrary web script or HTML allows remote attackers to inject arbitrary web script or HTML via Javascript events such as onmouseover in nested BBcode tags, as demonstrated using (1) email, (2) img, and (3) url tags."}], "problemTypes": [{"descriptions": [{"description": "n/a", "lang": "en", "type": "text"}]}], "providerMetadata": {"dateUpdated": "2018-10-10T18:57:01", "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca", "shortName": "mitre"}, "references": [{"name": "53782", "tags": ["vdb-entry", "x_refsource_OSVDB"], "url": "http://osvdb.org/53782"}, {"name": "8453", "tags": ["exploit", "x_refsource_EXPLOIT-DB"], "url": "https://www.exploit-db.com/exploits/8453"}, {"name": "34764", "tags": ["third-party-advisory", "x_refsource_SECUNIA"], "url": "http://secunia.com/advisories/34764"}, {"tags": ["x_refsource_CONFIRM"], "url": "http://www.webspell.org/index.php?site=news_comments&newsID=126&lang=uk"}, {"name": "34595", "tags": ["vdb-entry", "x_refsource_BID"], "url": "http://www.securityfocus.com/bid/34595"}, {"name": "20090416 webSPELL 4.2.0c XSS (BYPASS BBCODE) COOKIES STEALING VULNERABILITY", "tags": ["mailing-list", "x_refsource_BUGTRAQ"], "url": "http://www.securityfocus.com/archive/1/502732/100/0/threaded"}, {"tags": ["x_refsource_CONFIRM"], "url": "http://www.webspell.org/index.php?site=files&file=25"}, {"name": "webspell-bbcode-xss(49937)", "tags": ["vdb-entry", "x_refsource_XF"], "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/49937"}], "x_legacyV4Record": {"CVE_data_meta": {"ASSIGNER": "cve@mitre.org", "ID": "CVE-2009-1408", "STATE": "PUBLIC"}, "affects": {"vendor": {"vendor_data": [{"product": {"product_data": [{"product_name": "n/a", "version": {"version_data": [{"version_value": "n/a"}]}}]}, "vendor_name": "n/a"}]}}, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": {"description_data": [{"lang": "eng", "value": "Cross-site scripting (XSS) vulnerability in webSPELL 4.2.0c allows remote attackers to inject arbitrary web script or HTML allows remote attackers to inject arbitrary web script or HTML via Javascript events such as onmouseover in nested BBcode tags, as demonstrated using (1) email, (2) img, and (3) url tags."}]}, "problemtype": {"problemtype_data": [{"description": [{"lang": "eng", "value": "n/a"}]}]}, "references": {"reference_data": [{"name": "53782", "refsource": "OSVDB", "url": "http://osvdb.org/53782"}, {"name": "8453", "refsource": "EXPLOIT-DB", "url": "https://www.exploit-db.com/exploits/8453"}, {"name": "34764", "refsource": "SECUNIA", "url": "http://secunia.com/advisories/34764"}, {"name": "http://www.webspell.org/index.php?site=news_comments&newsID=126&lang=uk", "refsource": "CONFIRM", "url": "http://www.webspell.org/index.php?site=news_comments&newsID=126&lang=uk"}, {"name": "34595", "refsource": "BID", "url": "http://www.securityfocus.com/bid/34595"}, {"name": "20090416 webSPELL 4.2.0c XSS (BYPASS BBCODE) COOKIES STEALING VULNERABILITY", "refsource": "BUGTRAQ", "url": "http://www.securityfocus.com/archive/1/502732/100/0/threaded"}, {"name": "http://www.webspell.org/index.php?site=files&file=25", "refsource": "CONFIRM", "url": "http://www.webspell.org/index.php?site=files&file=25"}, {"name": "webspell-bbcode-xss(49937)", "refsource": "XF", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/49937"}]}}}, "adp": [{"providerMetadata": {"orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2024-08-07T05:13:25.475Z"}, "title": "CVE Program Container", "references": [{"name": "53782", "tags": ["vdb-entry", "x_refsource_OSVDB", "x_transferred"], "url": "http://osvdb.org/53782"}, {"name": "8453", "tags": ["exploit", "x_refsource_EXPLOIT-DB", "x_transferred"], "url": "https://www.exploit-db.com/exploits/8453"}, {"name": "34764", "tags": ["third-party-advisory", "x_refsource_SECUNIA", "x_transferred"], "url": "http://secunia.com/advisories/34764"}, {"tags": ["x_refsource_CONFIRM", "x_transferred"], "url": "http://www.webspell.org/index.php?site=news_comments&newsID=126&lang=uk"}, {"name": "34595", "tags": ["vdb-entry", "x_refsource_BID", "x_transferred"], "url": "http://www.securityfocus.com/bid/34595"}, {"name": "20090416 webSPELL 4.2.0c XSS (BYPASS BBCODE) COOKIES STEALING VULNERABILITY", "tags": ["mailing-list", "x_refsource_BUGTRAQ", "x_transferred"], "url": "http://www.securityfocus.com/archive/1/502732/100/0/threaded"}, {"tags": ["x_refsource_CONFIRM", "x_transferred"], "url": "http://www.webspell.org/index.php?site=files&file=25"}, {"name": "webspell-bbcode-xss(49937)", "tags": ["vdb-entry", "x_refsource_XF", "x_transferred"], "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/49937"}]}]}, "cveMetadata": {"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca", "assignerShortName": "mitre", "cveId": "CVE-2009-1408", "datePublished": "2009-04-24T14:00:00", "dateReserved": "2009-04-24T00:00:00", "dateUpdated": "2024-08-07T05:13:25.475Z", "state": "PUBLISHED"}, "dataType": "CVE_RECORD", "dataVersion": "5.1"}