Vulnerabilities > CVE-2005-2574 - Unspecified vulnerability in XMB Forum XMB 1.9.1

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
xmb-forum
nessus

Summary

xmb.php in XMB Forum 1.9.1 extracts and defines all provided variables, which allows remote attackers to modify arbitrary server variables such as _SERVER[REMOTE_ADDR].

Vulnerable Configurations

Part Description Count
Application
Xmb_Forum
1

Nessus

NASL familyCGI abuses
NASL idXMB_MULTIPLE_XSS.NASL
descriptionThe remote host is running XMB Forum, a web forum written in PHP. According to its banner, the version of XMB installed on the remote host suffers from cross-site scripting, SQL injection, and input validation vulnerabilities.
last seen2020-06-01
modified2020-06-02
plugin id17608
published2005-03-24
reporterThis script is Copyright (C) 2005-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/17608
titleXMB Forum < 1.9.10 Multiple Vulnerabilities

Statements

contributor
lastmodified2008-12-11
organizationXMB
statementXMB version 1.9.10 or later must be installed to prevent attacks described by this CVE. A patch is also included in third service pack for version 1.9.8 only. All other versions of XMB are vulnerable until upgraded. Upgrades are available at http://www.xmbforum.com/