Multiple cross-site scripting (XSS) vulnerabilities in geccBBlite 0.1 allow remote attackers to inject arbitrary web script or HTML via the postatoda parameter to (1) rispondi.php and (2) scrivi.php, which is not properly handled in forum.php.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published: 2010-02-22T20:00:00
Updated: 2024-08-07T07:08:38.125Z
Reserved: 2010-02-22T00:00:00
Link: CVE-2009-4649

No data.

Status : Deferred
Published: 2010-02-22T20:30:00.343
Modified: 2025-04-11T00:51:21.963
Link: CVE-2009-4649

No data.