CVE-2009-4649
geccBBlite 0.1 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in geccBBlite 0.1 allow remote attackers to inject arbitrary web script or HTML via the postatoda parameter to (1) rispondi.php and (2) scrivi.php, which is not properly handled in forum.php.
References (5)
Scores
EPSS
0.0034
EPSS Percentile
56.4%
Classification
CWE
CWE-79
Status
published
Affected Products (2)
geccbblite/geccbblite
n/a/n/a
Timeline
Published
Feb 22, 2010
Tracked Since
Feb 18, 2026