Vulnerability Name: | CVE-2006-1775 (CCN-25599) | ||||||||
Assigned: | 2006-04-03 | ||||||||
Published: | 2006-04-03 | ||||||||
Updated: | 2008-09-05 | ||||||||
Summary: | Multiple cross-site scripting (XSS) vulnerabilities in phpBB 2.0.19 allow remote attackers to inject arbitrary web script or HTML via the (1) Site Description field in (a) admin_board.php, the (2) Group name and (3) Group description fields in (b) admin_groups.php and (c) groupcp.php, the (4) Theme Name field in (d) admin_styles.php, and the (5) Rank Title field in (e) admin_ranks.php. Note: the profile.php/Current password vector is already covered by CVE-2006-1603. | ||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-1603 Source: MITRE Type: CNA CVE-2006-1775 Source: MISC Type: UNKNOWN http://osvdb.org/ref/24/24353-phpbb.txt Source: CCN Type: SA19494 phpBB "cur_password" Cross-Site Scripting Vulnerability Source: OSVDB Type: UNKNOWN 24354 Source: OSVDB Type: UNKNOWN 24355 Source: OSVDB Type: UNKNOWN 24356 Source: OSVDB Type: UNKNOWN 24357 Source: CCN Type: OSVDB ID: 24353 phpBB profile.php Current Password Field XSS Source: CCN Type: OSVDB ID: 24354 phpBB admin_board.php Site Description Field XSS Source: CCN Type: OSVDB ID: 24355 phpBB admin_groups.php New Group Multiple Field XSS Source: CCN Type: OSVDB ID: 24356 phpBB admin_styles.php Theme Name Field XSS Source: CCN Type: OSVDB ID: 24357 phpBB admin_ranks.php Rank Title Field XSS Source: CCN Type: phpBB Web site phpBB:: Creating Communities Source: CCN Type: BID-17355 PHPBB Profile.PHP Cross-Site Scripting Vulnerability Source: XF Type: UNKNOWN phpbb-multiple-scripts-xss(25599) | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |