CVE-2009-2172

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
23/06/2009
Last modified:
09/04/2025

Description

Cross-site scripting (XSS) vulnerability in forum/radioandtv.php in the Radio and TV Player addon for vBulletin allows remote registered users to inject arbitrary web script or HTML via the station parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dream:radio_and_tv_player_addon_for_vbulletin:*:*:*:*:*:*:*:*
cpe:2.3:a:jelsoft:vbulletin:*:*:*:*:*:*:*:*