CVE-2009-4994

Cross-site scripting (XSS) vulnerability in frmKBSearch.aspx in SmarterTools SmarterTrack before 4.0.3504 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 52%
VendorProductVersion
smartertoolssmartertrack
𝑥
≤ 4.0.3483
smartertoolssmartertrack
3.0.3040
smartertoolssmartertrack
3.1.3050
smartertoolssmartertrack
3.1.3089
smartertoolssmartertrack
3.5.3126
smartertoolssmartertrack
3.5.3159
smartertoolssmartertrack
3.5.3167
smartertoolssmartertrack
3.6.3216
smartertoolssmartertrack
3.6.3217
smartertoolssmartertrack
3.6.3229
smartertoolssmartertrack
3.6.3246
smartertoolssmartertrack
3.6.3267
smartertoolssmartertrack
3.6.3274
smartertoolssmartertrack
3.6.3309
smartertoolssmartertrack
3.6.3355
smartertoolssmartertrack
3.6.3411
smartertoolssmartertrack
3.6.3413
smartertoolssmartertrack
4.0.3387
smartertoolssmartertrack
4.0.3399
smartertoolssmartertrack
4.0.3411
smartertoolssmartertrack
4.0.3413
smartertoolssmartertrack
4.0.3435
𝑥
= Vulnerable software versions