CVE-2009-3539

Yourfreeworld Ultra Classifieds Pro - XSS

Title source: rule
STIX 2.1

Description

Multiple cross-site scripting (XSS) vulnerabilities in YourFreeWorld Ultra Classifieds Pro allow remote attackers to inject arbitrary web script or HTML via the (1) cname parameter to subclass.php and the (2) sn parameter to listads.php.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Moudi · textwebappsphp
https://www.exploit-db.com/exploits/34745
exploitdb WORKING POC VERIFIED
by Moudi · textwebappsphp
https://www.exploit-db.com/exploits/34744

References (3)

Core 3
Core References
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/1965
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35857

Scores

EPSS 0.0067
EPSS Percentile 71.5%

Details

CWE
CWE-79
Status published
Products (1)
yourfreeworld/ultra_classifieds_pro
Published Oct 02, 2009
Tracked Since Feb 18, 2026