CVE-2009-2172: XSS
Cross-site scripting (XSS) vulnerability in forum/radioandtv.php in the Radio and TV Player addon for vBulletin allows remote registered users to inject arbitrary web script or HTML via the station parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2172?
CVE-2009-2172 has a medium severity due to the potential for cross-site scripting attacks.
How do I fix CVE-2009-2172?
To fix CVE-2009-2172, ensure that the Radio and TV Player addon for vBulletin is updated to a secure version that patches this vulnerability.
Who is affected by CVE-2009-2172?
Registered users of the vBulletin forum with the Radio and TV Player addon are affected by CVE-2009-2172.
What type of vulnerability is CVE-2009-2172?
CVE-2009-2172 is a cross-site scripting (XSS) vulnerability that allows remote users to inject scripts.
What are the consequences of CVE-2009-2172 if exploited?
If exploited, CVE-2009-2172 can lead to unauthorized script execution in the context of a user's browser.