PT-2006-3444 · Aspbb · Aspbb

Teufel

·

Published

2006-05-20

·

Updated

2018-10-18

·

CVE-2006-2497

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions AspBB version 0.5.2
Description The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML. Specifically, the action parameter to "default.asp" and the get parameter to "profile.asp" are vulnerable.
Recommendations For AspBB version 0.5.2, consider restricting access to the vulnerable parameters action in "default.asp" and get in "profile.asp" to minimize the risk of exploitation. Avoid using these parameters until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-2497

Affected Products

Aspbb