xmb.php in XMB Forum 1.9.1 extracts and defines all provided variables, which allows remote attackers to modify arbitrary server variables such as _SERVER[REMOTE_ADDR].
References
Configurations
History
20 Nov 2024, 23:59
Type | Values Removed | Values Added |
---|---|---|
References | () http://forums.xmbforum.com/viewthread.php?tid=754523 - | |
References | () http://marc.info/?l=bugtraq&m=112361545228809&w=2 - | |
References | () https://docs.xmbforum2.com/index.php?title=Security_Issue_History - |
Information
Published : 2005-08-16 04:00
Updated : 2024-11-20 23:59
NVD link : CVE-2005-2574
Mitre link : CVE-2005-2574
CVE.ORG link : CVE-2005-2574
JSON object : View
Products Affected
xmb_forum
- xmb
CWE