CVE-2006-3795

Multiple cross-site scripting (XSS) vulnerabilities in DeluxeBB before 1.08 allow remote attackers to inject arbitrary web script or HTML via the (1) membercookie cookie in header.php and the (2) redirect parameter in misc.php.
Configurations

Configuration 1 (hide)

cpe:2.3:a:deluxebb:deluxebb:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:14

Type Values Removed Values Added
References () http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/047989.html - () http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/047989.html -
References () http://secunia.com/advisories/21116 - Vendor Advisory () http://secunia.com/advisories/21116 - Vendor Advisory
References () http://securityreason.com/securityalert/1254 - () http://securityreason.com/securityalert/1254 -
References () http://www.securityfocus.com/archive/1/440435/100/0/threaded - () http://www.securityfocus.com/archive/1/440435/100/0/threaded -
References () http://www.securityfocus.com/bid/19052 - () http://www.securityfocus.com/bid/19052 -
References () http://www.vupen.com/english/advisories/2006/2879 - () http://www.vupen.com/english/advisories/2006/2879 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/27836 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/27836 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/27837 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/27837 -

Information

Published : 2006-07-24 12:19

Updated : 2024-11-21 00:14


NVD link : CVE-2006-3795

Mitre link : CVE-2006-3795

CVE.ORG link : CVE-2006-3795


JSON object : View

Products Affected

deluxebb

  • deluxebb