Vulnerabilities > CVE-2005-2161 - Unspecified vulnerability in PHPbb Group PHPbb 2.0.16
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN phpbb-group
nessus
Summary
Cross-site scripting (XSS) vulnerability in phpBB 2.0.16 allows remote attackers to inject arbitrary web script or HTML via nested [url] tags.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family Debian Local Security Checks NASL id DEBIAN_DSA-768.NASL description A cross-site scripting vulnerability has been detected in phpBB2, a fully featured and skinnable flat webforum software, that allows remote attackers to inject arbitrary web script or HTML via nested tags. last seen 2020-06-01 modified 2020-06-02 plugin id 19317 published 2005-07-31 reporter This script is Copyright (C) 2005-2019 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/19317 title Debian DSA-768-1 : phpbb2 - missing input validation code #%NASL_MIN_LEVEL 80502 # # (C) Tenable Network Security, Inc. # # The descriptive text and package checks in this plugin were # extracted from Debian Security Advisory DSA-768. The text # itself is copyright (C) Software in the Public Interest, Inc. # include("compat.inc"); if (description) { script_id(19317); script_version("1.18"); script_cvs_date("Date: 2019/08/02 13:32:18"); script_cve_id("CVE-2005-2161"); script_xref(name:"DSA", value:"768"); script_name(english:"Debian DSA-768-1 : phpbb2 - missing input validation"); script_summary(english:"Checks dpkg output for the updated package"); script_set_attribute( attribute:"synopsis", value:"The remote Debian host is missing a security-related update." ); script_set_attribute( attribute:"description", value: "A cross-site scripting vulnerability has been detected in phpBB2, a fully featured and skinnable flat webforum software, that allows remote attackers to inject arbitrary web script or HTML via nested tags." ); script_set_attribute( attribute:"see_also", value:"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=317739" ); script_set_attribute( attribute:"see_also", value:"http://www.debian.org/security/2005/dsa-768" ); script_set_attribute( attribute:"solution", value: "Upgrade the phpbb2 packages. The old stable distribution (woody) does not contain phpbb2. For the stable distribution (sarge) this problem has been fixed in version 2.0.13-6sarge1." ); script_set_cvss_base_vector("CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N"); script_set_attribute(attribute:"plugin_type", value:"local"); script_set_attribute(attribute:"cpe", value:"p-cpe:/a:debian:debian_linux:phpbb2"); script_set_attribute(attribute:"cpe", value:"cpe:/o:debian:debian_linux:3.1"); script_set_attribute(attribute:"patch_publication_date", value:"2005/07/27"); script_set_attribute(attribute:"plugin_publication_date", value:"2005/07/31"); script_set_attribute(attribute:"vuln_publication_date", value:"2005/07/05"); script_end_attributes(); script_category(ACT_GATHER_INFO); script_copyright(english:"This script is Copyright (C) 2005-2019 Tenable Network Security, Inc."); script_family(english:"Debian Local Security Checks"); script_dependencies("ssh_get_info.nasl"); script_require_keys("Host/local_checks_enabled", "Host/Debian/release", "Host/Debian/dpkg-l"); exit(0); } include("audit.inc"); include("debian_package.inc"); if (!get_kb_item("Host/local_checks_enabled")) audit(AUDIT_LOCAL_CHECKS_NOT_ENABLED); if (!get_kb_item("Host/Debian/release")) audit(AUDIT_OS_NOT, "Debian"); if (!get_kb_item("Host/Debian/dpkg-l")) audit(AUDIT_PACKAGE_LIST_MISSING); flag = 0; if (deb_check(release:"3.1", prefix:"phpbb2", reference:"2.0.13-6sarge1")) flag++; if (deb_check(release:"3.1", prefix:"phpbb2-conf-mysql", reference:"2.0.13-6sarge1")) flag++; if (deb_check(release:"3.1", prefix:"phpbb2-languages", reference:"2.0.13-6sarge1")) flag++; if (flag) { if (report_verbosity > 0) security_warning(port:0, extra:deb_report_get()); else security_warning(0); exit(0); } else audit(AUDIT_HOST_NOT, "affected");
NASL family CGI abuses NASL id PHPBB_2_0_16.NASL description According to its banner, the remote host is running a version of phpBB that fails to sanitize BBCode containing nested URL tags, which enables attackers to cause arbitrary HTML and script code to be executed in a user last seen 2020-06-01 modified 2020-06-02 plugin id 18626 published 2005-07-06 reporter This script is Copyright (C) 2005-2018 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/18626 title phpBB < 2.0.17 Nested BBCode URL Tags XSS code # # (C) Tenable Network Security, Inc. # include("compat.inc"); if (description) { script_id(18626); script_version("1.17"); script_cve_id("CVE-2005-2161"); script_bugtraq_id(14151); script_name(english:"phpBB < 2.0.17 Nested BBCode URL Tags XSS"); script_set_attribute(attribute:"synopsis", value: "The remote web server contains a PHP application affected by a cross- site scripting issue." ); script_set_attribute(attribute:"description", value: "According to its banner, the remote host is running a version of phpBB that fails to sanitize BBCode containing nested URL tags, which enables attackers to cause arbitrary HTML and script code to be executed in a user's browser within the context of the affected site." ); script_set_attribute(attribute:"see_also", value:"https://www.securityfocus.com/archive/1/404300/30/0/threaded" ); script_set_attribute(attribute:"solution", value: "Upgrade to phpBB version 2.0.17 or later." ); script_set_cvss_base_vector("CVSS2#AV:N/AC:M/Au:S/C:N/I:P/A:N"); script_set_cvss_temporal_vector("CVSS2#E:H/RL:OF/RC:C"); script_set_attribute(attribute:"exploitability_ease", value:"No exploit is required"); script_set_attribute(attribute:"exploit_available", value:"false"); script_cwe_id(20, 74, 79, 442, 629, 711, 712, 722, 725, 750, 751, 800, 801, 809, 811, 864, 900, 928, 931, 990); script_set_attribute(attribute:"plugin_publication_date", value: "2005/07/06"); script_set_attribute(attribute:"vuln_publication_date", value: "2005/07/06"); script_cvs_date("Date: 2018/11/15 20:50:18"); script_set_attribute(attribute:"plugin_type", value:"remote"); script_set_attribute(attribute:"cpe",value:"cpe:/a:phpbb_group:phpbb"); script_end_attributes(); script_summary(english:"Checks for nested BBCode URL tags cross-site scripting vulnerability in phpBB <= 2.0.16"); script_category(ACT_GATHER_INFO); script_copyright(english:"This script is Copyright (C) 2005-2018 Tenable Network Security, Inc."); script_family(english:"CGI abuses"); script_dependencies("phpbb_detect.nasl"); script_exclude_keys("Settings/disable_cgi_scanning"); script_require_ports("Services/www", 80); script_require_keys("www/phpBB"); exit(0); } include("global_settings.inc"); include("misc_func.inc"); include("http.inc"); port = get_http_port(default:80); if (!can_host_php(port:port)) exit(0); # Test an install. install = get_kb_item(string("www/", port, "/phpBB")); if (isnull(install)) exit(0); matches = eregmatch(string:install, pattern:"^(.+) under (/.*)$"); if (!isnull(matches)) { ver = matches[1]; if (ver =~ "^([01]\..*|2\.0\.([0-9]|1[0-6])([^0-9]|$))") { security_note(port); set_kb_item(name: 'www/'+port+'/XSS', value: TRUE); } }