Record summary

CVE-2006-6421 has a selected CVSS score of 6.0; EIP currently links 1 catalogued exploit.

Description

Cross-site scripting (XSS) vulnerability in the private message box implementation (privmsg.php) in phpBB 2.0.x allows remote authenticated users to inject arbitrary web script or HTML via the "Message body" field in a message to a non-existent user.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBphpBB 2.0.21 - 'privmsg.php' HTML InjectionExploitDB exploitby DementialNot analyzed1 file
ExploitDB

PoC details

References

11