4.3
CVSSv2

CVE-2009-3060

Published: 03/09/2009 Updated: 09/09/2009
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in Joker Board (aka JBoard) 2.0 and previous versions allow remote malicious users to inject arbitrary web script or HTML via (1) the notice parameter to editform.php, (2) the edit_user_message parameter to core/edit_user_message.php, or (3) the user_title parameter to inc/head.inc.php, reachable through any PHP script.

Vulnerable Product Search on Vulmon Subscribe to Product

allpublication jboard