4.3
CVSSv2

CVE-2009-2401

Published: 09/07/2009 Updated: 19/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in PHPEcho CMS 2.0-rc3 allows remote malicious users to inject arbitrary web script or HTML via a forum post.

Vulnerable Product Search on Vulmon Subscribe to Product

phpecho cms phpecho cms 2.0-rc3

Exploits

PHPEcho CMS 20-rc3 (forum) XSS Cookie Stealing / Blind Vulnerability bug found by Jose Luis Gongora Fernandez (aka) JosS contact: sys-project[at]hotmailcom website: wwwhack0wncom/ - download: sourceforgenet/project/showfilesphp?group_id=186100 ~ [XSS] The forum allowed insert javascript code and html code PoC: "&gt ...