Unrated severityNVD Advisory· Published Jan 4, 2010· Updated Apr 23, 2026
CVE-2009-4554
CVE-2009-4554
Description
Multiple cross-site scripting (XSS) vulnerabilities in Snitz Forums 2000 3.4.07 allow remote attackers to inject arbitrary web script or HTML via (1) the url parameter to pop_send_to_friend.asp, related to a crafted onload attribute of an IMG element; or (2) an onload attribute in a sound tag.
Affected products
1- cpe:2.3:a:snitz_communications:snitz_forums_2000:3.4.07:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- www.securityfocus.com/bid/36710nvdExploit
- secunia.com/advisories/35733nvdVendor Advisory
- www.vupen.com/english/advisories/2009/2957nvdVendor Advisory
- www.securityfocus.com/archive/1/507207/100/0/threadednvd
- exchange.xforce.ibmcloud.com/vulnerabilities/53803nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/53804nvd
News mentions
0No linked articles in our index yet.