CVE-2009-2172

Radio and TV Player <vBulletin - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in forum/radioandtv.php in the Radio and TV Player addon for vBulletin allows remote registered users to inject arbitrary web script or HTML via the station parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by d3v1l · textwebappsphp
https://www.exploit-db.com/exploits/8965

Scores

EPSS 0.0040
EPSS Percentile 60.4%

Classification

CWE
CWE-79
Status published

Affected Products (2)

dream/radio_and_tv_player_addon_for_vbulletin
n/a/n/a

Timeline

Published Jun 23, 2009
Tracked Since Feb 18, 2026