Vulnerabilities > CVE-2004-2054 - Unspecified vulnerability in PHPbb Group PHPbb
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN phpbb-group
nessus
Summary
CRLF injection vulnerability in PhpBB 2.0.4 and 2.0.9 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via (1) the mode parameter to privmsg.php or (2) the redirect parameter to login.php.
Vulnerable Configurations
Nessus
NASL family | CGI abuses : XSS |
NASL id | PHPBB_SEARCH_AUTHOR_XSS.NASL |
description | The remote host is running a version of phpBB older than 2.0.10. phpBB contains a flaw that allows a remote cross-site scripting attack. This flaw exists because the application does not validate user-supplied input in the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 13840 |
published | 2004-07-26 |
reporter | This script is Copyright (C) 2004-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/13840 |
title | phpBB < 2.0.10 Multiple XSS |
code |
|
References
- http://marc.info/?l=bugtraq&m=109034476122723&w=2
- http://marc.info/?l=bugtraq&m=109034476122723&w=2
- http://secunia.com/advisories/12114
- http://secunia.com/advisories/12114
- http://www.securityfocus.com/bid/10753
- http://www.securityfocus.com/bid/10753
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16759
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16759