Unrated severityNVD Advisory· Published Aug 17, 2009· Updated Apr 23, 2026
CVE-2009-2783
CVE-2009-2783
Description
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.3.3 allow remote attackers to inject arbitrary web script or HTML via the (1) op parameter to modules/pm/viewpmsg.php and (2) query string to modules/profile/user.php.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- xoops.svn.sourceforge.net/viewvc/xoops/XoopsCore/trunk/htdocs/modules/pm/viewpmsg.phpnvdPatch
- marc.infonvdExploit
- www.securityfocus.com/bid/35895nvdExploit
- www.securitytracker.com/idnvdExploit
- secunia.com/advisories/36109nvdVendor Advisory
- www.senseofsecurity.com.au/advisories/SOS-09-005.pdfnvdURL Repurposed
- osvdb.org/56638nvd
- xoops.svn.sourceforge.net/viewvc/xoops/XoopsCore/trunk/htdocs/modules/pm/viewpmsg.phpnvd
News mentions
0No linked articles in our index yet.