Multiple cross-site scripting (XSS) vulnerabilities in WebCoreModule.ashx in RADactive I-Load before 2008.2.5.0 allow remote attackers to inject arbitrary web script or HTML via parameters with names beginning with __ (underscore underscore) sequences, which are incompatible with an XSS protection mechanism provided by Microsoft ASP.NET.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-07T06:31:09.610Z

Reserved: 2009-09-29T00:00:00

Link: CVE-2009-3450

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2009-09-29T15:30:00.530

Modified: 2025-04-09T00:30:58.490

Link: CVE-2009-3450

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.