MEDIUM
Cross-site scripting (XSS) vulnerability in NBBC before 1.4.2 allows remote attackers to inject arbitrary web script or HTML via an invalid URL in a BBCode img tag
Published Jun 25, 2009
4.3
MEDIUMCVSS 2.0
EPSS 1.22%
Description
Cross-site scripting (XSS) vulnerability in NBBC before 1.4.2 allows remote attackers to inject arbitrary web script or HTML via an invalid URL in a BBCode img tag.
Affected products
No data.
OR
- ≤ 1.4.1
- 1.0
- 1.0
- 1.0
- 1.0
- 1.0
- 1.0
- 1.1
- 1.2
- 1.3
- 1.3.1
- 1.3.2
- 1.3.3
- 1.3.4
- 1.4.0
- alpha
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- http://osvdb.org/55266 vdb-entryx_refsource_OSVDB
- http://secunia.com/advisories/35520 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://sourceforge.net/forum/message.php?msg_id=7455625 x_refsource_MISCPatch
- http://sourceforge.net/forum/message.php?msg_id=7456208 x_refsource_CONFIRMPatch
- http://sourceforge.net/tracker/?func=detail&aid=2809888&group_id=235382&atid=1096820 x_refsource_CONFIRMPatch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51288 vdb-entryx_refsource_XF
| Link | Providers | Tags |
|---|---|---|
| http://osvdb.org/55266 | vdb-entryx_refsource_OSVDB | |
| http://secunia.com/advisories/35520 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://sourceforge.net/forum/message.php?msg_id=7455625 | x_refsource_MISCPatch | |
| http://sourceforge.net/forum/message.php?msg_id=7456208 | x_refsource_CONFIRMPatch | |
| http://sourceforge.net/tracker/?func=detail&aid=2809888&group_id=235382&atid=1096820 | x_refsource_CONFIRMPatch | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/51288 | vdb-entryx_refsource_XF |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 25, 2009
Updated Aug 7, 2024
Reserved Jun 25, 2009
Link CVE-2009-2217
CISA Vulnrichment
Updated n/a