Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.20379
Category:Web application abuses
Title:phpBB <= 2.0.18 Multiple Cross-Site Scripting Flaws
Summary:The remote web server contains a PHP application that is affected by; several flaws.;; Description :;; According to its version number, the remote version of this software; is vulnerable to Javascript injection issues using 'url' bbcode tags; and, if HTML tags are enabled, HTML more generally.
Description:Summary:
The remote web server contains a PHP application that is affected by
several flaws.

Description :

According to its version number, the remote version of this software
is vulnerable to Javascript injection issues using 'url' bbcode tags
and, if HTML tags are enabled, HTML more generally.

Vulnerability Impact:
This may allow an attacker to inject hostile Javascript into
the forum system, to steal cookie credentials or misrepresent site content. When the form is
submitted the malicious Javascript will be incorporated into dynamically generated content.

Solution:
Upgrade to phpBB version 2.0.19 or later.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N

CopyrightCopyright (C) 2006 David Maciejak

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.