2.6
CVSSv2

CVE-2009-0455

Published: 11/02/2009 Updated: 08/08/2017
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 265
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the anonymous comments feature in lib-comment.php in glFusion 1.1.0, 1.1.1, and previous versions versions allows remote malicious users to inject arbitrary web script or HTML via the username parameter to comment.php.

Vulnerable Product Search on Vulmon Subscribe to Product

glfusion glfusion 1.1.0

glfusion glfusion

Exploits

source: wwwsecurityfocuscom/bid/33683/info glFusion is prone to an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied data Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials and to co ...