CVE-2008-5399
10.12.2008, 06:44
Cross-site scripting (XSS) vulnerability in the listonlineusers (aka "Who's online") component in mvnForum before 1.2.1 GA allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
Vendor | Product | Version |
---|---|---|
mvnforum | mvnforum | 𝑥 ≤ 1.2 |
mvnforum | mvnforum | 1.0.0:beta1 |
mvnforum | mvnforum | 1.0.0:beta2 |
mvnforum | mvnforum | 1.0.0:beta3 |
mvnforum | mvnforum | 1.0.0:rc1 |
mvnforum | mvnforum | 1.0.0:rc2 |
mvnforum | mvnforum | 1.0.0:rc3_01 |
mvnforum | mvnforum | 1.0.0:rc4 |
mvnforum | mvnforum | 1.0.2.:ga |
mvnforum | mvnforum | 1.1:ga |
𝑥
= Vulnerable software versions
References