Multiple cross-site scripting (XSS) vulnerabilities in Devsyn Open Bulletin Board (OpenBB) 1.0.6 allow remote attackers to inject arbitrary web script or HTML via (1) the FID parameter in board.php and (2) the TID parameter in read.php. NOTE: the SQL injection issues are already covered by CVE-2005-1612 (read.php) and CVE-2005-2566 (board.php).
References
Configurations
History
No history.
Information
Published : 2006-04-29 10:02
Updated : 2024-02-28 10:42
NVD link : CVE-2006-2088
Mitre link : CVE-2006-2088
CVE.ORG link : CVE-2006-2088
JSON object : View
Products Affected
devsyn
- open_bulletin_board
CWE