Back to Database
Status published
Medium
CVE-2009-4994
Cross-site scripting (XSS) vulnerability in frmKBSearch.aspx in SmarterTools SmarterTrack before...
Vulnerability Description
Cross-site scripting (XSS) vulnerability in frmKBSearch.aspx in SmarterTools SmarterTrack before 4.0.3504 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2009-4994
Credits & Attribution
No credits recorded in the NVD database.
References
More from smartertools
View All →CVE-2021-43977
SmarterTools SmarterMail 16.x through 100.x before 100.0.7803 allows XSS....
Medium
6.1
CVE-2021-40377
SmarterTools SmarterMail 16.x before build 7866 has stored XSS. The...
Medium
5.4
CVE-2021-32234
SmarterTools SmarterMail 16.x through 100.x before 100.0.7803 allows remote code...
Critical
9.8
CVE-2021-32233
SmarterTools SmarterMail before Build 7776 allows XSS....
Medium
6.1
CVE-2020-29548
An issue was discovered in SmarterTools SmarterMail through 100.0.7537. Meddler-in-the-middle...
High
8.1
Affected Vendor
smartertools
View all reports →Affected Software
smartertrack
Vulnerable Versions:
0, 3.0.3040, 3.1.3050, 3.1.3089, 3.5.3126, 3.5.3159, 3.5.3167, 3.6.3216, 3.6.3217, 3.6.3229, 3.6.3246, 3.6.3267, 3.6.3274, 3.6.3309, 3.6.3355, 3.6.3411, 3.6.3413, 4.0.3387, 4.0.3399, 4.0.3411, 4.0.3413, 4.0.3435
Timeline
Official Publish:
August 25th, 2010
Last Modified:
September 16th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.