Multiple cross-site scripting (XSS) vulnerabilities in Snitz Forums 2000 3.4.07 allow remote attackers to inject arbitrary web script or HTML via (1) the url parameter to pop_send_to_friend.asp, related to a crafted onload attribute of an IMG element; or (2) an onload attribute in a sound tag.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2010-01-04T21:00:00

Updated: 2024-08-07T07:08:37.916Z

Reserved: 2010-01-04T00:00:00

Link: CVE-2009-4554

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2010-01-04T21:30:00.360

Modified: 2018-10-10T19:49:18.417

Link: CVE-2009-4554

cve-icon Redhat

No data.