Vulnerabilities > Ektron > Cms4000 NET > Medium

DATE CVE VULNERABILITY TITLE RISK
2009-12-30 CVE-2009-4473 Cross-Site Scripting vulnerability in Ektron Cms4000.Net
Multiple cross-site scripting (XSS) vulnerabilities in WorkArea/ContentDesigner/ekformsiframe.aspx in Ektron CMS400.NET 7.6.1.53 and 7.6.6.47, and possibly 7.52 through 7.66sp2, allow remote attackers to inject arbitrary web script or HTML via the (1) css, (2) eca, (3) id, and (4) skin parameters.
network
ektron CWE-79
4.3