CVE-2009-3192
Linkorcms < 1.2 - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in index.php in LinkorCMS 1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the searchstr parameter in a search action; or the (2) nikname, (3) realname, (4) homepage, or (5) city parameter in a registration action.
Scores
EPSS
0.0026
EPSS Percentile
49.4%
Classification
CWE
CWE-79
Status
published
Affected Products (4)
linkorcms/linkorcms
< 1.2
linkorcms/linkorcms
linkorcms/linkorcms
n/a/n/a
Timeline
Published
Sep 15, 2009
Tracked Since
Feb 18, 2026