36380vdb entry
http://osvdb.org/36380 CVE-2007-3212
Beehive Forum 0.7.1 - 'links.php' Multiple Cross-Site Scripting Vulnerabilities
Record summary
CVE-2007-3212 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.
Description
Multiple cross-site scripting (XSS) vulnerabilities in links.php in Beehive Forum 0.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) viewmode, (2) fid, and (3) sort_dir parameters, different vectors than CVE-2005-4460.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBBeehive Forum 0.7.1 - 'links.php' Multiple Cross-Site Scripting VulnerabilitiesExploitDB exploitby Ory SegalNot analyzed1 file
References
725634Third-party advisory
http://secunia.com/advisories/25634 dragoslungu.com
http://www.dragoslungu.com/2007/06/10/beehive-zero-vulnerabilities-myth-busted 24413vdb entry
http://www.securityfocus.com/bid/24413 ADV-2007-2146vdb entry
http://www.vupen.com/english/advisories/2007/2146 beehive-forum-links-xss(34827)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/34827 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-3212