CVE-2009-3204
Stivaforum Stiva Forum - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in Stiva Forum 1.0 allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) demo.php and (2) forum.php, and the PATH_INFO to (3) include_forum.php.
References (5)
Scores
EPSS
0.0033
EPSS Percentile
55.5%
Classification
CWE
CWE-79
Status
published
Affected Products (2)
stivaforum/stiva_forum
n/a/n/a
Timeline
Published
Sep 16, 2009
Tracked Since
Feb 18, 2026