3.5
CVSSv2

CVE-2009-2327

Published: 05/07/2009 Updated: 19/09/2017
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 355
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in add_voting.php in KerviNet Forum 1.1 and previous versions allows remote authenticated users to inject arbitrary web script or HTML via the v_variant1 parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

max kervin kervinet forum

Exploits

dork: "Copyright KerviNet" eLwaux(c) 20062009 ## ## ## ## Blind SQLinj /indexphp ------------------------------------------------------------------------------------------------- if($_COOKIE['user_enter']=="auto") { $enter_login=$_COOKIE['enter_login']; $enter_parol=$_COOKIE['enter_parol']; $mysql->query("SELECT name, pass, status FROM users ...