PT-2008-3260 · Woltlab · Woltlab Burning Board+1
Published
2008-04-09
·
Updated
2018-10-11
·
CVE-2008-1716
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
WoltLab Burning Board version 3.0.5
WoltLab Community Framework (WCF) version 1.0.6
Description
A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via the
page and form parameters. These parameters are not properly handled when they are reflected back in an error message.Recommendations
For WoltLab Burning Board version 3.0.5, update the WoltLab Community Framework (WCF) to a version that properly handles the
page and form parameters to prevent XSS attacks.
For WoltLab Community Framework (WCF) version 1.0.6, ensure that error messages properly sanitize the page and form parameters to prevent reflection of malicious input.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Woltlab Burning Board
Woltlab Community Framework