Vulnerabilities > CVE-2006-1034 - Cross-Site Scripting vulnerability in Woltlab Burning Board

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
woltlab
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in Woltlab Burning Board (wBB) allow remote attackers to inject arbitrary web script or HTML via (1) the username parameter to galerie_index.php and possibly (2) galerie_onfly.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. The second vector might not be XSS.

Exploit-Db

  • descriptionWoltlab Burning Board 1.1.1/2.x galerie_onfly.php XSS. CVE-2006-1034. Webapps exploit for php platform
    idEDB-ID:27323
    last seen2016-02-03
    modified2006-02-27
    published2006-02-27
    reporterbotan
    sourcehttps://www.exploit-db.com/download/27323/
    titleWoltlab Burning Board 1.1.1/2.x galerie_onfly.php XSS
  • descriptionWoltlab Burning Board 1.1.1/2.x galerie_index.php username Parameter XSS. CVE-2006-1034. Webapps exploit for php platform
    idEDB-ID:27322
    last seen2016-02-03
    modified2006-02-27
    published2006-02-27
    reporterbotan
    sourcehttps://www.exploit-db.com/download/27322/
    titleWoltlab Burning Board 1.1.1/2.x galerie_index.php username Parameter XSS