Vulnerabilities > CVE-2006-0407 - HTML Injection vulnerability in AZ Bulletin Board

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
azbb
exploit available

Summary

Cross-site scripting (XSS) vulnerability in post.php in AZ Bulletin Board (AZbb) 1.1.00 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) nickname parameter and (2) an iframe tag in the topic parameter. NOTE: the original disclosure specified the name parameter, but a correction was later provided. NOTE: followup posts have both disputed and confirmed the original claim.

Exploit-Db

descriptionAZ Bulletin Board 1.0.x/1.1 Post.PHP HTML Injection Vulnerabilities. CVE-2006-0407. Webapps exploit for php platform
idEDB-ID:27120
last seen2016-02-03
modified2006-01-23
published2006-01-23
reporterRoozbeh Afrasiabi
sourcehttps://www.exploit-db.com/download/27120/
titleAZ Bulletin Board 1.0.x/1.1 Post.PHP HTML Injection Vulnerabilities