Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2006-1603

Опубликовано: 04 апр. 2006
Источник: debian

Описание

Cross-site scripting (XSS) vulnerability in profile.php in phpBB 2.0.19 allows remote attackers to inject arbitrary web script or HTML via the cur_password parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
phpbb2not-affectedpackage

Примечания

  • <jvw> jmm: unable to everify, the variable in question is only printed

  • at one single page, and there it doesn't get taken from GET nor POST in my tests

  • <jvw> and, shock, the password isn't saved unhashed in the DB, so having

  • javascript in your password can't be exposed otherwise

  • <jvw> I'd forget about it unless someone comes with a proof of concept

Связанные уязвимости

ubuntu
больше 19 лет назад

Cross-site scripting (XSS) vulnerability in profile.php in phpBB 2.0.19 allows remote attackers to inject arbitrary web script or HTML via the cur_password parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

nvd
больше 19 лет назад

Cross-site scripting (XSS) vulnerability in profile.php in phpBB 2.0.19 allows remote attackers to inject arbitrary web script or HTML via the cur_password parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

github
больше 3 лет назад

Cross-site scripting (XSS) vulnerability in profile.php in phpBB 2.0.19 allows remote attackers to inject arbitrary web script or HTML via the cur_password parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.