Vulnerabilities > CVE-2007-3963 - Cross-Site Scripting vulnerability in UseBB PHP_SELF

047910
CVSS 9.3 - CRITICAL
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
usebb
critical
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in UseBB 1.0.7, and possibly other 1.0.x versions, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF) to (1) upgrade-0-2-3.php, (2) upgrade-0-3.php, or (3) upgrade-0-4.php in install/, a different vulnerability than CVE-2005-4193.

Exploit-Db

  • descriptionUseBB 1.0.7 install/upgrade-0-2-3.php PHP_SELF Parameter XSS. CVE-2007-3963. Webapps exploit for php platform
    idEDB-ID:30323
    last seen2016-02-03
    modified2007-07-20
    published2007-07-20
    reporters4mi
    sourcehttps://www.exploit-db.com/download/30323/
    titleUseBB 1.0.7 install/upgrade-0-2-3.php PHP_SELF Parameter XSS
  • descriptionUseBB 1.0.7 install/upgrade-0-3.php PHP_SELF Parameter XSS. CVE-2007-3963. Webapps exploit for php platform
    idEDB-ID:30324
    last seen2016-02-03
    modified2007-07-20
    published2007-07-20
    reporters4mi
    sourcehttps://www.exploit-db.com/download/30324/
    titleUseBB 1.0.7 install/upgrade-0-3.php PHP_SELF Parameter XSS