Multiple cross-site scripting (XSS) vulnerabilities in activatemember in mvnForum 1.0 GA and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) member and (2) activatecode parameters.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Mvnforum | Mvnforum | 1.0.0_beta1 (including) | 1.0.0_beta1 (including) |
| Mvnforum | Mvnforum | 1.0.0_beta2 (including) | 1.0.0_beta2 (including) |
| Mvnforum | Mvnforum | 1.0.0_beta3 (including) | 1.0.0_beta3 (including) |
| Mvnforum | Mvnforum | 1.0.0_rc1 (including) | 1.0.0_rc1 (including) |
| Mvnforum | Mvnforum | 1.0.0_rc2 (including) | 1.0.0_rc2 (including) |
| Mvnforum | Mvnforum | 1.0.0_rc3_01 (including) | 1.0.0_rc3_01 (including) |
| Mvnforum | Mvnforum | 1.0.0_rc4 (including) | 1.0.0_rc4 (including) |
| Mvnforum | Mvnforum | 1.0.0_rc4_04 (including) | 1.0.0_rc4_04 (including) |
| Mvnforum | Mvnforum | 1.0_ga (including) | 1.0_ga (including) |