4.3
CVSSv2

CVE-2008-1173

Published: 06/03/2008 Updated: 11/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in account-inbox.php in TorrentTrader Classic 1.08 allows remote malicious users to inject arbitrary web script or HTML via the msg parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

torrenttrader torrenttrader 1.08

torrenttrader torrenttrader classic 1.08

Exploits

source: wwwsecurityfocuscom/bid/28082/info TorrentTrader is prone to an HTML-injection vulnerability because it fails to adequately sanitize user-supplied input Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials and ...