CVE-2009-2217
25.06.2009, 23:14
Cross-site scripting (XSS) vulnerability in NBBC before 1.4.2 allows remote attackers to inject arbitrary web script or HTML via an invalid URL in a BBCode img tag.
Vendor | Product | Version |
---|---|---|
phantom-inker | nbbc | 𝑥 ≤ 1.4.1 |
phantom-inker | nbbc | 1.0 |
phantom-inker | nbbc | 1.0:rc |
phantom-inker | nbbc | 1.0:rc2 |
phantom-inker | nbbc | 1.0:rc3 |
phantom-inker | nbbc | 1.0:rc4 |
phantom-inker | nbbc | 1.0:rc5 |
phantom-inker | nbbc | 1.1 |
phantom-inker | nbbc | 1.2 |
phantom-inker | nbbc | 1.3 |
phantom-inker | nbbc | 1.3.1 |
phantom-inker | nbbc | 1.3.2 |
phantom-inker | nbbc | 1.3.3 |
phantom-inker | nbbc | 1.3.4 |
phantom-inker | nbbc | 1.4.0 |
𝑥
= Vulnerable software versions
References