CVE-2007-5564
Simple Php Forum - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in NSSboard (formerly Simple PHP Forum) 6.1 allow remote attackers to inject arbitrary web script or HTML via (1) HTML tags when BBcode is disabled; or the (2) user, (3) email, or (4) Real Name fields in a profile.
References (4)
Scores
EPSS
0.0029
EPSS Percentile
51.7%
Classification
CWE
CWE-79
Status
draft
Affected Products (1)
simple_php_forum/simple_php_forum
Timeline
Published
Oct 18, 2007
Tracked Since
Feb 18, 2026