Vulnerabilities > CVE-2006-1768 - Cross-Site Scripting vulnerability in Tritanium Scripts Tritanium Bulletin Board 1.2.3

047910
CVSS 5.1 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
high complexity
tritanium-scripts
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in register.php in Tritanium Bulletin Board (TBB) 1.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) newuser_name, (2) newuser_email, and (3) newuser_hp parameters in the faction=register mode in index.php. Succesful exploitation requires that "register_globals" is enabled.

Vulnerable Configurations

Part Description Count
Application
Tritanium_Scripts
1

Exploit-Db

descriptionTritanium Bulletin Board 1.2.3 Multiple Cross-Site Scripting Vulnerabilities. CVE-2006-1768. Webapps exploit for php platform
idEDB-ID:27626
last seen2016-02-03
modified2006-04-11
published2006-04-11
reporterd4igoro
sourcehttps://www.exploit-db.com/download/27626/
titleTritanium Bulletin Board 1.2.3 - Multiple Cross-Site Scripting Vulnerabilities