PT-2006-1903 · E107 · E107+1

Published

2006-02-23

·

Updated

2018-10-18

·

CVE-2006-0857

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions e107 version 0.7.2 Chatbox Plugin version 1.0
Description A cross-site scripting issue allows remote attackers to inject arbitrary HTML or web script via a Chatbox. This can be achieved by using a SCRIPT element.
Recommendations For e107 version 0.7.2, consider disabling the Chatbox Plugin until a patch is available. For Chatbox Plugin version 1.0, restrict access to the Chatbox feature to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2006-0857

Affected Products

Chatbox Plugin
E107