PT-2006-1148 · Phpbb · Phpbb

Maksymilian Arciemowicz

·

Published

2006-01-05

·

Updated

2011-03-07

·

CVE-2006-0063

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: phpBB version 2.0.19
Description: A cross-site scripting (XSS) issue exists when the "Allowed HTML tags" option is enabled, allowing remote attackers to inject arbitrary web script or HTML via permitted HTML tags containing ' (single quote) characters and active attributes like onmouseover.
Recommendations: For phpBB version 2.0.19, disable the "Allowed HTML tags" option to prevent exploitation until a fix is available. As a temporary workaround, consider restricting the use of active attributes in permitted HTML tags.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2006-0063

Affected Products

Phpbb