{"api_version":"1","generated_at":"2026-07-23T09:00:14+00:00","cve":"CVE-2009-1408","urls":{"html":"https://cve.report/CVE-2009-1408","api":"https://cve.report/api/cve/CVE-2009-1408.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-1408","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-1408"},"summary":{"title":"CVE-2009-1408","description":"Cross-site scripting (XSS) vulnerability in webSPELL 4.2.0c allows remote attackers to inject arbitrary web script or HTML allows remote attackers to inject arbitrary web script or HTML via Javascript events such as onmouseover in nested BBcode tags, as demonstrated using (1) email, (2) img, and (3) url tags.","state":"PUBLISHED","assigner":"mitre","published_at":"2009-04-24 14:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"https://www.exploit-db.com/exploits/8453","name":"https://www.exploit-db.com/exploits/8453","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"webSPELL 4.2.0c Bypass BBCode XSS Cookie Stealing Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.webspell.org/index.php?site=files&file=25","name":"http://www.webspell.org/index.php?site=files&file=25","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"SecurityFix 2009-04-04d  »  Download  »  webSPELL.org CMS","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.webspell.org/index.php?site=news_comments&newsID=126&lang=uk","name":"http://www.webspell.org/index.php?site=news_comments&newsID=126&lang=uk","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"webSPELL.org CMS » Free Content Management System","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/49937","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/49937","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/34595","name":"http://www.securityfocus.com/bid/34595","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch"],"title":"webSPELL BBCode HTML Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://osvdb.org/53782","name":"http://osvdb.org/53782","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/archive/1/502732/100/0/threaded","name":"http://www.securityfocus.com/archive/1/502732/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/34764","name":"http://secunia.com/advisories/34764","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"webSPELL BBCode Script Insertion Vulnerability - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-1408","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-1408","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"1408","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"webspell","cpe5":"webspell","cpe6":"4.2.0c","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T05:13:25.475Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"53782","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/53782"},{"name":"8453","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/8453"},{"name":"34764","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/34764"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.webspell.org/index.php?site=news_comments&newsID=126&lang=uk"},{"name":"34595","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/34595"},{"name":"20090416 webSPELL 4.2.0c XSS (BYPASS BBCODE) COOKIES STEALING VULNERABILITY","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/502732/100/0/threaded"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.webspell.org/index.php?site=files&file=25"},{"name":"webspell-bbcode-xss(49937)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/49937"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-04-16T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in webSPELL 4.2.0c allows remote attackers to inject arbitrary web script or HTML allows remote attackers to inject arbitrary web script or HTML via Javascript events such as onmouseover in nested BBcode tags, as demonstrated using (1) email, (2) img, and (3) url tags."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-10T18:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"53782","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/53782"},{"name":"8453","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/8453"},{"name":"34764","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/34764"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.webspell.org/index.php?site=news_comments&newsID=126&lang=uk"},{"name":"34595","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/34595"},{"name":"20090416 webSPELL 4.2.0c XSS (BYPASS BBCODE) COOKIES STEALING VULNERABILITY","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/502732/100/0/threaded"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.webspell.org/index.php?site=files&file=25"},{"name":"webspell-bbcode-xss(49937)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/49937"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-1408","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in webSPELL 4.2.0c allows remote attackers to inject arbitrary web script or HTML allows remote attackers to inject arbitrary web script or HTML via Javascript events such as onmouseover in nested BBcode tags, as demonstrated using (1) email, (2) img, and (3) url tags."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"53782","refsource":"OSVDB","url":"http://osvdb.org/53782"},{"name":"8453","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/8453"},{"name":"34764","refsource":"SECUNIA","url":"http://secunia.com/advisories/34764"},{"name":"http://www.webspell.org/index.php?site=news_comments&newsID=126&lang=uk","refsource":"CONFIRM","url":"http://www.webspell.org/index.php?site=news_comments&newsID=126&lang=uk"},{"name":"34595","refsource":"BID","url":"http://www.securityfocus.com/bid/34595"},{"name":"20090416 webSPELL 4.2.0c XSS (BYPASS BBCODE) COOKIES STEALING VULNERABILITY","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/502732/100/0/threaded"},{"name":"http://www.webspell.org/index.php?site=files&file=25","refsource":"CONFIRM","url":"http://www.webspell.org/index.php?site=files&file=25"},{"name":"webspell-bbcode-xss(49937)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/49937"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-1408","datePublished":"2009-04-24T14:00:00.000Z","dateReserved":"2009-04-24T00:00:00.000Z","dateUpdated":"2024-08-07T05:13:25.475Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-04-24 14:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:webspell:webspell:4.2.0c:*:*:*:*:*:*:*","matchCriteriaId":"45223AEF-D151-4C08-993F-1537BC02DA40"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"1408","Ordinal":"1","Title":"CVE-2009-1408","CVE":"CVE-2009-1408","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"1408","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in webSPELL 4.2.0c allows remote attackers to inject arbitrary web script or HTML allows remote attackers to inject arbitrary web script or HTML via Javascript events such as onmouseover in nested BBcode tags, as demonstrated using (1) email, (2) img, and (3) url tags.","Type":"Description","Title":"CVE-2009-1408"},{"CveYear":"2009","CveId":"1408","Ordinal":"2","NoteData":"2009-04-24","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"1408","Ordinal":"3","NoteData":"2018-10-10","Type":"Other","Title":"Modified"}]}}}