CVE-2009-3195
Jce-tech Auction Rss Content Script - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in JCE-Tech Auction RSS Content Script 3.0 allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) rss.php and (2) search.php.
Exploits (2)
Scores
EPSS
0.0080
EPSS Percentile
73.9%
Classification
CWE
CWE-79
Status
published
Affected Products (2)
jce-tech/auction_rss_content_script
n/a/n/a
Timeline
Published
Sep 15, 2009
Tracked Since
Feb 18, 2026