VYPR
Unrated severityNVD Advisory· Published Jun 22, 2009· Updated Apr 23, 2026

CVE-2009-2162

CVE-2009-2162

Description

Cross-site scripting (XSS) vulnerability in the XOOPS MANIAC PukiWikiMod module 1.6.6.2 and earlier for XOOPS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

PukiWikiMod 1.6.6.2 and earlier contains a cross-site scripting vulnerability allowing arbitrary script execution in a user's browser.

Vulnerability

PukiWikiMod from XOOPS Maniac, a content management module for XOOPS, versions 1.6.6.2 and earlier, contains a cross-site scripting (XSS) vulnerability via unspecified vectors [1][2]. The vulnerability is present in the module's handling of user input.

Exploitation

An attacker can exploit this vulnerability by tricking a user into visiting a crafted URL or interacting with malicious input. The exact mechanism is not disclosed in the available references, but it is typical for XSS vulnerabilities to require user interaction [1][2].

Impact

Successful exploitation allows an attacker to execute arbitrary script or HTML in the context of the victim's browser. This can lead to theft of sensitive data, session hijacking, or defacement [1][2].

Mitigation

The developer has not released a specific patched version, but recommends updating to the latest version available from the vendor [1][2]. As of the publication date (2009-06-19), no other workarounds are documented.

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

16
  • Ishii/Pukiwikimod16 versions
    cpe:2.3:a:ishii:pukiwikimod:*:*:*:*:*:*:*:*+ 15 more
    • cpe:2.3:a:ishii:pukiwikimod:*:*:*:*:*:*:*:*range: <=1.6.6.2
    • cpe:2.3:a:ishii:pukiwikimod:1.5.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ishii:pukiwikimod:1.5.3:*:*:*:*:*:*:*
    • cpe:2.3:a:ishii:pukiwikimod:1.5.5:*:*:*:*:*:*:*
    • cpe:2.3:a:ishii:pukiwikimod:1.5.6:*:*:*:*:*:*:*
    • cpe:2.3:a:ishii:pukiwikimod:1.5.6.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ishii:pukiwikimod:1.5.6.2:*:*:*:*:*:*:*
    • cpe:2.3:a:ishii:pukiwikimod:1.6.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ishii:pukiwikimod:1.6.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ishii:pukiwikimod:1.6.2:*:*:*:*:*:*:*
    • cpe:2.3:a:ishii:pukiwikimod:1.6.3:*:*:*:*:*:*:*
    • cpe:2.3:a:ishii:pukiwikimod:1.6.4:*:*:*:*:*:*:*
    • cpe:2.3:a:ishii:pukiwikimod:1.6.5:*:*:*:*:*:*:*
    • cpe:2.3:a:ishii:pukiwikimod:1.6.5.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ishii:pukiwikimod:1.6.6:*:*:*:*:*:*:*
    • (no CPE)range: <=1.6.6.2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.