CVE-2008-2561

Properties

Published:
05.06.2008
Updated:
17.08.2008
Patch available:
Severity:
Medium
CVSS vector:
(AV:N/AC:M/Au:N/C:N/I:P/A:N)
Product:
fourtwosevenbb: 427bb

Vulnerability description

Multiple cross-site scripting (XSS) vulnerabilities in 427BB 2.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to (a) register.php, (b) reminder.php, and (c) search.php; the (2) uname, (3) email, and (4) email2 parameters to register.php; the (5) email parameter to reminder.php; and the (6) keywords parameter to search.php.

References:

MILW0RM: http://www.milw0rm.com/exploits/5742
SECUNIA: http://secunia.com/advisories/30520