Multiple cross-site scripting (XSS) vulnerabilities in Snitz Forums 2000 3.4.07 allow remote attackers to inject arbitrary web script or HTML via (1) the url parameter to pop_send_to_friend.asp, related to a crafted onload attribute of an IMG element; or (2) an onload attribute in a sound tag.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2010-01-04T21:00:00

Updated: 2018-10-10T18:57:01

Reserved: 2010-01-04T00:00:00


Link: CVE-2009-4554

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2010-01-04T21:30:00.360

Modified: 2018-10-10T19:49:18.417


Link: CVE-2009-4554

JSON object: View

cve-icon Redhat Information

No data.

CWE