VulnerabilityModified
CVE-2009-3539
Multiple cross-site scripting (XSS) vulnerabilities in YourFreeWorld Ultra Classifieds Pro allow remote attackers to inject arbitrary web script or HTML via the (1) cname parameter to subclass.php and the (2) sn parameter to listads.php.
MEDIUM 4.3EPSS 1.52%
Does this matter?
Lower severity and a low EPSS score (1.52%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in YourFreeWorld Ultra Classifieds Pro allow remote attackers to inject arbitrary web script or HTML via the (1) cname parameter to subclass.php and the (2) sn parameter to listads.php.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.52% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- yourfreeworld/ultra classifieds pro
- Source
- cve@mitre.org
References
- http://packetstormsecurity.org/0907-exploits/ultraclassifieds-xss.txtExploit
- http://secunia.com/advisories/35857Vendor Advisory
- http://www.vupen.com/english/advisories/2009/1965Vendor Advisory
- http://packetstormsecurity.org/0907-exploits/ultraclassifieds-xss.txtExploit
- http://secunia.com/advisories/35857Vendor Advisory
- http://www.vupen.com/english/advisories/2009/1965Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.