Vulnerabilities > CVE-2004-1809 - Unspecified vulnerability in PHPbb Group PHPbb
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN phpbb-group
nessus
Summary
Cross-site scripting (XSS) vulnerability in phpBB 2.0.6d and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) postdays parameter to viewtopic.php or (2) topicdays parameter to viewforum.php.
Vulnerable Configurations
Nessus
NASL family | CGI abuses : XSS |
NASL id | PHPBB_XSS.NASL |
description | There are cross-site scripting vulnerabilities in the files |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 12093 |
published | 2004-03-14 |
reporter | This script is Copyright (C) 2004-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/12093 |
title | phpBB < 2.0.7 Multiple XSS |
code |
|
References
- http://marc.info/?l=bugtraq&m=107920498205324&w=2
- http://marc.info/?l=bugtraq&m=107920498205324&w=2
- http://secunia.com/advisories/11121
- http://secunia.com/advisories/11121
- http://www.osvdb.org/4257
- http://www.osvdb.org/4257
- http://www.osvdb.org/4259
- http://www.osvdb.org/4259
- http://www.phpbb.com/support/documents.php?mode=changelog#206
- http://www.phpbb.com/support/documents.php?mode=changelog#206
- http://www.securityfocus.com/bid/9865
- http://www.securityfocus.com/bid/9865
- http://www.securityfocus.com/bid/9866
- http://www.securityfocus.com/bid/9866
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15464
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15464