{"api_version":"1","generated_at":"2026-07-23T12:25:19+00:00","cve":"CVE-2009-0532","urls":{"html":"https://cve.report/CVE-2009-0532","api":"https://cve.report/api/cve/CVE-2009-0532.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-0532","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-0532"},"summary":{"title":"CVE-2009-0532","description":"Cross-site scripting (XSS) vulnerability in password.php in Scripts For Sites (SFS) EZ Baby allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving the u2 parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.","state":"PUBLISHED","assigner":"mitre","published_at":"2009-02-11 20:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/33635","name":"http://www.securityfocus.com/bid/33635","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Scripts for Sites EZ Baby 'password.php' Cross Site Scripting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/48547","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/48547","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://secunia.com/advisories/33989","name":"http://secunia.com/advisories/33989","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Scripts For Sites Products Cross-Site Scripting Vulnerability - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-0532","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-0532","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"532","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"scripts-for-sites","cpe5":"ez_baby","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T04:40:04.026Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ezbaby-password-xss(48547)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/48547"},{"name":"33635","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/33635"},{"name":"33989","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/33989"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-02-05T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in password.php in Scripts For Sites (SFS) EZ Baby allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving the u2 parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-07T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"ezbaby-password-xss(48547)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/48547"},{"name":"33635","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/33635"},{"name":"33989","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/33989"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-0532","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in password.php in Scripts For Sites (SFS) EZ Baby allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving the u2 parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ezbaby-password-xss(48547)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/48547"},{"name":"33635","refsource":"BID","url":"http://www.securityfocus.com/bid/33635"},{"name":"33989","refsource":"SECUNIA","url":"http://secunia.com/advisories/33989"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-0532","datePublished":"2009-02-11T20:00:00.000Z","dateReserved":"2009-02-11T00:00:00.000Z","dateUpdated":"2024-08-07T04:40:04.026Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-02-11 20:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:scripts-for-sites:ez_baby:-:*:*:*:*:*:*:*","matchCriteriaId":"5E1B6FC8-7B5B-41B0-AC73-94F4567A19BF"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"532","Ordinal":"1","Title":"CVE-2009-0532","CVE":"CVE-2009-0532","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"532","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in password.php in Scripts For Sites (SFS) EZ Baby allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving the u2 parameter.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.","Type":"Description","Title":"CVE-2009-0532"},{"CveYear":"2009","CveId":"532","Ordinal":"2","NoteData":"2009-02-11","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"532","Ordinal":"3","NoteData":"2017-08-07","Type":"Other","Title":"Modified"}]}}}