Vulnerabilities > CVE-2007-3590 - Cross-Site Scripting vulnerability in B1G B1Gbb 2.24

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
b1g
exploit available

Summary

Cross-site scripting (XSS) vulnerability in visitenkarte.php in b1gBB 2.24.0 allows remote attackers to inject arbitrary web script or HTML via the user parameter.

Vulnerable Configurations

Part Description Count
Application
B1G
1

Exploit-Db

descriptionb1gbb 2.24.0 (SQL Injection / XSS) Remote Vulnerabilities. CVE-2007-3589,CVE-2007-3590. Webapps exploit for php platform
fileexploits/php/webapps/4122.txt
idEDB-ID:4122
last seen2016-01-31
modified2007-06-28
platformphp
port
published2007-06-28
reporterGoLd_M
sourcehttps://www.exploit-db.com/download/4122/
titleb1gbb 2.24.0 SQL Injection / XSS Remote Vulnerabilities
typewebapps