CVE-2009-1175
Banshee - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in apps/web/vs_diag.cgi in the DAAP extension in Banshee 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the server parameter, which is not properly handled in an error message.
Scores
EPSS
0.0032
EPSS Percentile
54.5%
Classification
CWE
CWE-79
Status
published
Affected Products (2)
banshee-project/banshee
n/a/n/a
Timeline
Published
Mar 31, 2009
Tracked Since
Feb 18, 2026