PT-2006-1148 · Phpbb · Phpbb
Maksymilian Arciemowicz
·
Published
2006-01-05
·
Updated
2011-03-07
·
CVE-2006-0063
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
phpBB version 2.0.19
Description:
A cross-site scripting (XSS) issue exists when the "Allowed HTML tags" option is enabled, allowing remote attackers to inject arbitrary web script or HTML via permitted HTML tags containing ' (single quote) characters and active attributes like
onmouseover.Recommendations:
For phpBB version 2.0.19, disable the "Allowed HTML tags" option to prevent exploitation until a fix is available. As a temporary workaround, consider restricting the use of active attributes in permitted HTML tags.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phpbb