Vulnerabilities > CVE-2005-2441 - Cross-Site Scripting vulnerability in VBZooM Forum

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
vbzoom
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in VBzoom allow remote attackers to inject arbitrary web script and HTML via the (1) UserName parameter to profile.php or (2) UserID parameter to login.php.

Vulnerable Configurations

Part Description Count
Application
Vbzoom
1

Exploit-Db

  • descriptionVBZoom 1.0/1.11 profile.php UserName Parameter XSS. CVE-2005-2441. Webapps exploit for php platform
    idEDB-ID:26049
    last seen2016-02-03
    modified2005-07-29
    published2005-07-29
    reporteralmaster
    sourcehttps://www.exploit-db.com/download/26049/
    titleVBZoom 1.0/1.11 profile.php UserName Parameter XSS
  • descriptionVBZoom 1.0/1.11 login.php UserID Parameter XSS. CVE-2005-2441 . Webapps exploit for php platform
    idEDB-ID:26050
    last seen2016-02-03
    modified2005-07-29
    published2005-07-29
    reporteralmaster
    sourcehttps://www.exploit-db.com/download/26050/
    titleVBZoom 1.0/1.11 login.php UserID Parameter XSS