Cross-site scripting (XSS) vulnerability in usercp_register.php for phpBB 2.0.13 allows remote attackers to inject arbitrary web script or HTML by setting the (1) allowhtml, (2) allowbbcode, or (3) allowsmilies parameters to inject HTML into signatures for personal messages, possibly when they are processed by privmsg.php or viewtopic.php.
References
Configurations
History
20 Nov 2024, 23:55
Type | Values Removed | Values Added |
---|---|---|
References | () http://neosecurityteam.tk/index.php?pagina=advisories&id=8 - | |
References | () http://secunia.com/advisories/14475 - Patch | |
References | () http://securitytracker.com/id?1013362 - |
Information
Published : 2005-05-02 04:00
Updated : 2024-11-20 23:55
NVD link : CVE-2005-0673
Mitre link : CVE-2005-0673
CVE.ORG link : CVE-2005-0673
JSON object : View
Products Affected
phpbb_group
- phpbb
CWE