vendor:
Radio and TV Add-on
by:
d3v1l [Avram Marius]
7,5
CVSS
HIGH
XSS, Iframe injection and Redirect
79, 94, 601
CWE
Product Name: Radio and TV Add-on
Affected Version From: All versions
Affected Version To: All versions
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
vBulletin Radio and TV Player Add-On (all version) – XSS , Iframe injection and Redirect Vulnerability
This vulnerability allows an attacker to inject malicious code into the vulnerable application. The malicious code can be used to redirect users to malicious websites, inject iframes, or execute arbitrary JavaScript code.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in the application.