4.3
CVSSv2

CVE-2009-2172

Published: 23/06/2009 Updated: 29/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in forum/radioandtv.php in the Radio and TV Player addon for vBulletin allows remote registered users to inject arbitrary web script or HTML via the station parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

dream radio_and_tv_player_addon_for_vbulletin

Exploits

vBulletin Radio and TV Player Add-On (all version) - XSS , Iframe injection and Redirect Vulnerability About:- Radio and TV Add-on will add a radio and TV library to your forum Features:- - Users can add / delete / edit own stations For more info about this plugin See - wwwvbulletinorg/forum/showthreadphp?t=152037&page=2 No ...