Description
Cross-site scripting (XSS) vulnerability in list.php in PHPB2B 4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the q parameter in a search action.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by H4ckCity Security Team · textwebappsphp
https://www.exploit-db.com/exploits/36484
References (3)
Core 3
Core References
Exploit x_refsource_misc
http://packetstormsecurity.org/files/view/108280/phpb2b-xss.txt
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/72082
Exploit vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/51221
Scores
EPSS
0.0064
EPSS Percentile
70.9%
Details
CWE
CWE-79
Status
published
Products (9)
phpb2b/phpb2b
1.0
phpb2b/phpb2b
2.0
phpb2b/phpb2b
3.0
phpb2b/phpb2b
3.1
phpb2b/phpb2b
3.2
phpb2b/phpb2b
3.3
phpb2b/phpb2b
3.4
phpb2b/phpb2b
4.0
phpb2b/phpb2b
< 4.1
Published
Sep 23, 2012
Tracked Since
Feb 18, 2026