PT-2005-3454 · Gbx · Gravity Board X
Retrogod
·
Published
2005-08-16
·
Updated
2016-10-18
·
CVE-2005-2563
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Gravity Board X (GBX) version 1.1
Description
The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML. Specifically, the
board id parameter to deletethread.php and the template are vulnerable.Recommendations
For Gravity Board X (GBX) version 1.1, avoid using the
board id parameter in the deletethread.php endpoint and restrict access to the template until a fix is available.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gravity Board X