20050308 failles dans ProjectBB v0.4.5.1mailing list
http://marc.info/?l=bugtraq&m=111031893610270&w=2 CVE-2005-0650
ProjectBB 0.4.5.1 - Multiple Cross-Site Scripting Vulnerabilities
Record summary
CVE-2005-0650 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.
Description
Multiple cross-site scripting (XSS) vulnerabilities in ProjectBB 0.4.5.1 allow remote attackers to inject arbitrary web script or HTML via (1) the pages parameter to divers.php (incorrectly referred to as "drivers.php" by some sources), (2) in the search feature text area, (3) forum name, (4) site name or (5) the maximum avatar size in the option section, (5) new category or (6) new forum fields in the forum section.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBProjectBB 0.4.5.1 - Multiple Cross-Site Scripting VulnerabilitiesExploitDB exploitby benji lemienNot analyzed1 file
References
714533Third-party advisory
http://secunia.com/advisories/14533 1013332vdb entry
http://securitytracker.com/id?1013332 12709vdb entry
http://www.securityfocus.com/bid/12709 ADV-2005-0223vdb entry
http://www.vupen.com/english/advisories/2005/0223 projectbb-multiple-xss(19556)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/19556 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2005-0650