20041213 Multiple XSS Vulnerabilities in several UBB.Thread Versionsmailing list
http://archives.neohapsis.com/archives/fulldisclosure/2004-12/0239.html CVE-2004-2509
UBBCentral UBB.Threads 6.2.3/6.5 - 'calendar.php?Cat' Cross-Site Scripting
Record summary
CVE-2004-2509 has a selected CVSS score of 4.3; EIP currently links 3 catalogued exploits.
Description
Cross-site scripting (XSS) vulnerabilities in (1) calendar.php, (2) login.php, and (3) online.php in Infopop UBB.Threads 6.2.3 and 6.5 allow remote attackers to inject arbitrary web script or HTML via the Cat parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 3
Proofs of concept
3Catalogued exploits
ExploitDBUBBCentral UBB.Threads 6.2.3/6.5 - 'calendar.php?Cat' Cross-Site ScriptingExploitDB exploitby dw. & ms.Not analyzed1 file
ExploitDBUBBCentral UBB.Threads 6.2.3/6.5 - 'login.php?Cat' Cross-Site ScriptingExploitDB exploitby dw. & ms.Not analyzed1 file
ExploitDBUBBCentral UBB.Threads 6.2.3/6.5 - 'online.php?Cat' Cross-Site ScriptingExploitDB exploitby dw. & ms.Not analyzed1 file
References
913452Third-party advisory
http://secunia.com/advisories/13452 1012503vdb entry
http://securitytracker.com/id?1012503 12365vdb entry
http://www.osvdb.org/12365 12366vdb entry
http://www.osvdb.org/12366 12367vdb entry
http://www.osvdb.org/12367 11900vdb entry
http://www.securityfocus.com/bid/11900 ubbthreads-multiple-scripts-xss(18432)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/18432 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-2509