CVE-2009-3152 Information

Description

Multiple cross-site scripting (XSS) vulnerabilities in becommunity/community/index.php in NTSOFT BBS E-Market Professional allow remote attackers to inject arbitrary web script or HTML via the (1) page (2) bt_code and (3) b_no parameters in a board view action.

Reference

http://packetstormsecurity.org/0907-exploits/ntsoft-xss.txt http://secunia.com/advisories/26117 http://www.securityfocus.com/bid/35893 https://exchange.xforce.ibmcloud.com/vulnerabilities/52157

Share on: