Vulnerabilities
Vulnerable Software
Webspell:  >> Webspell  >> 4.2.0c  Security Vulnerabilities
Directory traversal vulnerability in src/func/language.php in webSPELL 4.2.0e and earlier allows remote attackers to include and execute arbitrary local .php files via a .. (dot dot) in a language cookie. NOTE: this can be leveraged for SQL injection by including awards.php.
CVSS Score
6.8
EPSS Score
0.024
Published
2009-06-04
Cross-site scripting (XSS) vulnerability in webSPELL 4.2.0c allows remote attackers to inject arbitrary web script or HTML allows remote attackers to inject arbitrary web script or HTML via Javascript events such as onmouseover in nested BBcode tags, as demonstrated using (1) email, (2) img, and (3) url tags.
CVSS Score
4.3
EPSS Score
0.095
Published
2009-04-24


Contact Us

Shodan ® - All rights reserved