Multiple cross-site scripting (XSS) vulnerabilities in geccBBlite 0.1 allow remote attackers to inject arbitrary web script or HTML via the postatoda parameter to (1) rispondi.php and (2) scrivi.php, which is not properly handled in forum.php.
                
            Metrics
Affected Vendors & Products
References
        History
                    No history.
Status: PUBLISHED
Assigner: mitre
Published: 2010-02-22T20:00:00
Updated: 2024-08-07T07:08:38.125Z
Reserved: 2010-02-22T00:00:00
Link: CVE-2009-4649
No data.
Status : Deferred
Published: 2010-02-22T20:30:00.343
Modified: 2025-04-11T00:51:21.963
Link: CVE-2009-4649
No data.