sn4k3.23

2 exploits Active since May 2006
CVE-2006-2359 EXPLOITDB text WRITEUP
phpBB Chart mod - Cross-Site Scripting via id Parameter
Cross-site scripting (XSS) vulnerability in charts.php in the Chart mod for phpBB allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this issue might be resultant from SQL injection.
CVE-2006-2360 EXPLOITDB text WRITEUP
phpBB Chart mod - SQL Injection via id Parameter
SQL injection vulnerability in charts.php in the Chart mod for phpBB allows remote attackers to execute arbitrary SQL commands via the id parameter.