23283Third-party advisory
http://secunia.com/advisories/23283 CVE-2006-6421
phpBB 2.0.21 - 'privmsg.php' HTML Injection
Record summary
CVE-2006-6421 has a selected CVSS score of 6.0; EIP currently links 1 catalogued exploit.
Description
Cross-site scripting (XSS) vulnerability in the private message box implementation (privmsg.php) in phpBB 2.0.x allows remote authenticated users to inject arbitrary web script or HTML via the "Message body" field in a message to a non-existent user.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBphpBB 2.0.21 - 'privmsg.php' HTML InjectionExploitDB exploitby DementialNot analyzed1 file
References
112005Third-party advisory
http://securityreason.com/securityalert/2005 phpbb.comConfirmation
http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=489624 20061207 phpbb 2.0.x [xss]mailing list
http://www.securityfocus.com/archive/1/453774/100/0/threaded 20070111 phpBB (privmsg.php) XSS Exploitmailing list
http://www.securityfocus.com/archive/1/456579/100/0/threaded 20070111 Re: phpBB (privmsg.php) XSS Exploitmailing list
http://www.securityfocus.com/archive/1/456728/100/100/threaded 20070112 Re: phpBB (privmsg.php) XSS Exploitmailing list
http://www.securityfocus.com/archive/1/456784/100/100/threaded 21806vdb entry
http://www.securityfocus.com/bid/21806 22001vdb entry
http://www.securityfocus.com/bid/22001 phpbb-privmsgphp-xss(30776)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/30776 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2006-6421