Unrated severityNVD Advisory· Published Dec 30, 2009· Updated Apr 23, 2026
CVE-2009-4460
CVE-2009-4460
Description
Multiple cross-site scripting (XSS) vulnerabilities in Auto-Surf Traffic Exchange Script 1.1 allow remote attackers to inject arbitrary web script or HTML via the rid parameter to (1) index.php, (2) faq.php, and (3) register.php.
Affected products
1- cpe:2.3:a:ljscripts:auto-surf_traffic_exchange_script:1.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- www.exploit-db.com/exploits/10616nvdExploit
- secunia.com/advisories/37894nvdVendor Advisory
- osvdb.org/61285nvd
- osvdb.org/61286nvd
- osvdb.org/61287nvd
News mentions
0No linked articles in our index yet.