PT-2005-1674 · 427Bb · 427Bb

Th3_R@V3N

·

Published

2005-03-01

·

Updated

2017-07-11

·

CVE-2005-0629

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions 427BB version 2.2
Description The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML via the user or Avatar parameters in the profile.php file.
Recommendations For version 2.2, update to a version that includes a fix for this issue to prevent exploitation. As a temporary workaround, consider restricting input for the user and Avatar parameters to minimize the risk of XSS attacks.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0629

Affected Products

427Bb