Vulnerabilities > CVE-2006-6421 - Input Validation vulnerability in PHPBB

047910
CVSS 6.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
phpbb-group
nessus
exploit available

Summary

Cross-site scripting (XSS) vulnerability in the private message box implementation (privmsg.php) in phpBB 2.0.x allows remote authenticated users to inject arbitrary web script or HTML via the "Message body" field in a message to a non-existent user.

Exploit-Db

descriptionphpBB 2.0.21 Privmsg.PHP HTML Injection Vulnerability. CVE-2006-6421. Webapps exploit for php platform
idEDB-ID:29442
last seen2016-02-03
modified2007-01-11
published2007-01-11
reporterDemential
sourcehttps://www.exploit-db.com/download/29442/
titlephpBB 2.0.21 - Privmsg.PHP HTML Injection Vulnerability

Nessus

NASL familyCGI abuses
NASL idPHPBB_2022.NASL
descriptionThe version of phpBB installed on the remote host fails to properly block
last seen2020-06-01
modified2020-06-02
plugin id23968
published2007-01-03
reporterThis script is Copyright (C) 2007-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/23968
titlephpBB < 2.0.22 Multiple Vulnerabilities