![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2006-2755 |
Description: | Cross-site scripting (XSS) vulnerability in index.php in UBBThreads 5.x and earlier allows remote attackers to inject arbitrary web script or HTML via the debug parameter, as demonstrated by stealing MD5 hashes of passwords. |
Test IDs: | 1.3.6.1.4.1.25623.1.0.56872 |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2006-2755 BugTraq ID: 18152 http://www.securityfocus.com/bid/18152 Bugtraq: 20060528 Advisory: UBBThreads 5.x,6.x Multiple File InclusionVulnerabilities. (Google Search) http://www.securityfocus.com/archive/1/435288/100/0/threaded Bugtraq: 20060529 UBBThreads 5.x,6.x md5 hash disclosure (Google Search) http://www.securityfocus.com/archive/1/435296/100/0/threaded http://www.nukedx.com/?viewdoc=40 http://securityreason.com/securityalert/1007 XForce ISS Database: ubbthreads-index-xss(26870) https://exchange.xforce.ibmcloud.com/vulnerabilities/26870 |