← Back

CVE-2009-4995

nvd nist
Published: Aug 25, 2010Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Cross-site scripting (XSS) vulnerability in frmTickets.aspx in SmarterTools SmarterTrack before 4.0.3504 allows remote attackers to inject arbitrary web script or HTML via the email address field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Affected (22)

1 product
Smartertrack
Configuration A
22 vulnerable
Vulnerable SoftwareAffected Versions
Smartertools
Up to 4.0.3483
Version 3.0.3040
Version 3.1.3050
Version 3.1.3089
Version 3.5.3126
Version 3.5.3159
Version 3.5.3167
Version 3.6.3216
Version 3.6.3217
Version 3.6.3229
Version 3.6.3246
Version 3.6.3267
Version 3.6.3274
Version 3.6.3309
Version 3.6.3355
Version 3.6.3411
Version 3.6.3413
Version 4.0.3387
Version 4.0.3399
Version 4.0.3411
Version 4.0.3413
Version 4.0.3435

References (2)

Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.