PoC Index

CVE-2009-4320

MEDIUM 4.3EPSS 1.1%

Cross-site scripting (XSS) vulnerability in searchform.php in The Next Generation of Genealogy Sitebuilding (TNG) 7.1.2 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.

CVSS v2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
1.06% chance of exploitation in the next 30 days, 62th percentile
Published
2009-12-14
Updated
2024-08-07

Proof-of-concept exploits (1)

References

Related