CVE-2009-4859
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD
Description
Multiple cross-site scripting (XSS) vulnerabilities in Online Work Order Suite (OWOS) Lite Edition 3.10 allow remote attackers to inject arbitrary web script or HTML via the show parameter to (1) default.asp and (2) report.asp, and the (3) go parameter to login.asp.
Affected (1)
Products: Onlinetechtools.com: Owos Lite
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.10 |
References (4)
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Timeline
No history available yet.