Description
Multiple cross-site scripting (XSS) vulnerabilities in Woltlab Burning Board (wBB) allow remote attackers to inject arbitrary web script or HTML via (1) the username parameter to galerie_index.php and possibly (2) galerie_onfly.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. The second vector might not be XSS.
Exploits (2)
References (1)
Core 1
Core References
Exploit vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/16843
Scores
EPSS
0.0027
EPSS Percentile
50.2%
Details
Status
published
Products (13)
woltlab/burning_board
1.1.1
woltlab/burning_board
2.0_beta_3
woltlab/burning_board
2.0_beta_4
woltlab/burning_board
2.0_beta_5
woltlab/burning_board
2.0_rc1
woltlab/burning_board
2.0_rc2
woltlab/burning_board
2.2.2
woltlab/burning_board
2.3.1
woltlab/burning_board
2.3.3
woltlab/burning_board
2.4
... and 3 more
Published
Mar 07, 2006
Tracked Since
Feb 18, 2026