CVE-2009-4347
17.12.2009, 17:30
Cross-site scripting (XSS) vulnerability in daloradius-users/login.php in daloRADIUS 0.9-8 and earlier allows remote attackers to inject arbitrary web script or HTML via the error parameter.
| Vendor | Product | Version |
|---|---|---|
| liran_tal | daloradius | 𝑥 ≤ 0.9-8 |
| liran_tal | daloradius | 0.7 |
| liran_tal | daloradius | 0.8 |
| liran_tal | daloradius | 0.9 |
| liran_tal | daloradius | 0.9-1 |
| liran_tal | daloradius | 0.9-2 |
| liran_tal | daloradius | 0.9-3 |
| liran_tal | daloradius | 0.9-4 |
| liran_tal | daloradius | 0.9-5 |
| liran_tal | daloradius | 0.9-6 |
| liran_tal | daloradius | 0.9-7 |
| liran_tal | daloradius | 0.9-7:rc1 |
| liran_tal | daloradius | 0.9-7:rc2 |
𝑥
= Vulnerable software versions
References