CVE Database
/

CVE-2006-1775

Back to search

CVE-2006-1775

Published: Apr 13, 2006

Modified: Sep 16, 2024

PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in phpBB 2.0.19 allow remote attackers to inject arbitrary web script or HTML via the (1) Site Description field in (a) admin_board.php, the (2) Group name and (3) Group description fields in (b) admin_groups.php and (c) groupcp.php, the (4) Theme Name field in (d) admin_styles.php, and the (5) Rank Title field in (e) admin_ranks.php. NOTE: the profile.php/Current password vector is already covered by CVE-2006-1603.

VendorProductVersions

n/a

n/a

affected
n/a

References

24354
vdb-entry
x_refsource_OSVDB
24357
vdb-entry
x_refsource_OSVDB
24355
vdb-entry
x_refsource_OSVDB
24356
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now