PT-2004-2951 · Phpbb · Phpbb
Published
2004-07-19
·
Updated
2017-07-11
·
CVE-2004-2055
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
PhpBB versions 2.0.4 through 2.0.9
Description
The issue is related to a cross-site scripting (XSS) vulnerability. It affects the search.php file and allows remote attackers to inject arbitrary HTML or web script via the
search author parameter.Recommendations
For versions 2.0.4 through 2.0.9, update to a version that fixes this issue to prevent exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Phpbb