Vulnerability Name: | CVE-2004-1809 (CCN-15464) | ||||||||
Assigned: | 2004-03-13 | ||||||||
Published: | 2004-03-13 | ||||||||
Updated: | 2017-07-11 | ||||||||
Summary: | Cross-site scripting (XSS) vulnerability in phpBB 2.0.6d and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) postdays parameter to viewtopic.php or (2) topicdays parameter to viewforum.php. | ||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Sat Mar 13 2004 - 11:20:18 CST phpBB 2.0.6d && Earlier Security Issues Source: MITRE Type: CNA CVE-2004-1809 Source: BUGTRAQ Type: UNKNOWN 20040313 phpBB 2.0.6d && Earlier Security Issues Source: CCN Type: SA11121 phpBB SQL Injection and Cross Site Scripting Vulnerabilities Source: SECUNIA Type: Patch 11121 Source: OSVDB Type: UNKNOWN 4257 Source: OSVDB Type: UNKNOWN 4259 Source: CCN Type: OSVDB ID: 4257 phpBB viewforum.php topicdays Parameter XSS Source: CCN Type: OSVDB ID: 4259 phpBB viewtopic.php postdays Parameter XSS Source: CCN Type: phpBB Web site phpBB.com:: Creating Communities Source: CONFIRM Type: UNKNOWN http://www.phpbb.com/support/documents.php?mode=changelog#206 Source: BID Type: Patch 9865 Source: CCN Type: BID-9865 PHPBB ViewTopic.PHP "postdays" Cross-Site Scripting Vulnerability Source: BID Type: Patch 9866 Source: CCN Type: BID-9866 PHPBB ViewForum.PHP "topicdays" Cross-Site Scripting Vulnerability Source: XF Type: UNKNOWN phpbb-viewforum-viewtopic-xss(15464) Source: XF Type: UNKNOWN phpbb-viewforum-viewtopic-xss(15464) | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |