CVE-2009-4848
Toutvirtual Virtualiq - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in ToutVirtual VirtualIQ Pro 3.2 build 7882 and 3.5 build 8691 allow remote attackers to inject arbitrary web script or HTML via the (1) userId parameter to tvserver/server/user/setPermissions.jsp, (2) deptName parameter to tvserver/server/user/addDepartment.jsp, (3) ID parameter to tvserver/server/inventory/inventoryTabs.jsp, (4) reportName parameter to tvserver/reports/virtualIQAdminReports.do, or (5) middleName parameter in a save action to tvserver/user/user.do.
Scores
EPSS
0.0024
EPSS Percentile
46.2%
Classification
CWE
CWE-79
Status
published
Affected Products (3)
toutvirtual/virtualiq
toutvirtual/virtualiq
n/a/n/a
Timeline
Published
May 07, 2010
Tracked Since
Feb 18, 2026