Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.802351
Category:Web application abuses
Title:XOOPS 'text' and 'message' Parameter Cross-Site Scripting Vulnerabilities
Summary:XOOPS is prone to cross site scripting vulnerabilities.
Description:Summary:
XOOPS is prone to cross site scripting vulnerabilities.

Vulnerability Insight:
The flaws are due to improper validation of user-supplied input to

- The 'text' parameter to include/formdhtmltextarea_preview.php (when 'html'
is set to '1'),

- The '[img]' BBCode tag in the 'message' parameter to pmlite.php script,
which allows attacker to execute arbitrary HTML and script code on the
user's browser session in the security context of an affected site.

Vulnerability Impact:
Successful exploitation will allow remote attackers to insert arbitrary HTML
and script code, which will be executed in a user's browser session in the context of an affected site.

Affected Software/OS:
XOOPS version 2.5.1a and prior.

Solution:
Upgrade to XOOPS version 2.5.3 or later.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2011-4565
BugTraq ID: 49995
http://www.securityfocus.com/bid/49995
https://www.htbridge.ch/advisory/multiple_xss_in_xoops_web_application_platform.html
http://secunia.com/advisories/46238
XForce ISS Database: xoops-formdhtmltextareapreview-xss(70378)
https://exchange.xforce.ibmcloud.com/vulnerabilities/70378
XForce ISS Database: xoops-pmlite-xss(70377)
https://exchange.xforce.ibmcloud.com/vulnerabilities/70377
CopyrightCopyright (C) 2011 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.