20050422 [SePro Bugtraq] WBB - WoltLab Burning Board <= 2.3.1 - XSSmailing list
http://marc.info/?l=bugtraq&m=111420516900814&w=2 CVE-2005-1285
WoltLab Burning Board 2.3.1 - 'thread.php' Cross-Site Scripting
Record summary
CVE-2005-1285 has a selected CVSS score of 6.8; EIP currently links 1 catalogued exploit.
Description
Cross-site scripting (XSS) vulnerability in thread.php in WoltLab Burning Board 2.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the hilight parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBWoltLab Burning Board 2.3.1 - 'thread.php' Cross-Site ScriptingExploitDB exploitby deluxe89Not analyzed1 file
References
515058Third-party advisory
http://secunia.com/advisories/15058 1013790vdb entry
http://securitytracker.com/id?1013790 13325vdb entry
http://www.securityfocus.com/bid/13325 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2005-1285