Vulnerabilities > CVE-2005-3412 - HTML Injection vulnerability in Elite Forum Elite Forum 1.0.0.0
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
NONE Integrity impact
PARTIAL Availability impact
NONE Summary
Cross-site scripting (XSS) vulnerability in Elite Forum 1.0.0.0 allows remote attackers to inject arbitrary web script or HTML via a Post Reply to a topic, in which the reply contains a javascript: URL in an <img> tag.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Elite Forum 1.0 HTML Injection Vulnerability. CVE-2005-3412. Webapps exploit for php platform |
id | EDB-ID:26447 |
last seen | 2016-02-03 |
modified | 2005-11-01 |
published | 2005-11-01 |
reporter | gladiator |
source | https://www.exploit-db.com/download/26447/ |
title | Elite Forum 1.0 HTML Injection Vulnerability |
References
- http://marc.info/?l=full-disclosure&m=113083841308736&w=2
- http://secunia.com/advisories/17341
- http://securityreason.com/securityalert/136
- http://www.h4cky0u.org/advisories/HYSA-2005-009-elite-forum.txt
- http://www.securityfocus.com/archive/1/415400/30/0/threaded
- http://www.securityfocus.com/bid/15257
- http://www.vupen.com/english/advisories/2005/2260