Required CVE Record Information
Description
Multiple cross-site scripting (XSS) vulnerabilities in versatileBulletinBoard (vBB) 1.0.0 RC2 allow remote attackers to inject arbitrary web script or HTML via (1) the url parameter in dereferrer.php and (2) the file parameter in imagewin.php.
References 7 Total
- osvdb.org: 19971 vdb-entry
- osvdb.org: 19970 vdb-entry
- marc.info: 20051010 versatileBulletinBoard V1.0.0 RC2 (possibly prior versions) mailing-list
- osvdb.org: 19969 vdb-entry
- http://rgod.altervista.org/versatile100RC2.html
- securityfocus.com: 15073 vdb-entry
- secunia.com: 17174 third-party-advisory
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 7 Total
- osvdb.org: 19971 vdb-entryx_transferred
- osvdb.org: 19970 vdb-entryx_transferred
- marc.info: 20051010 versatileBulletinBoard V1.0.0 RC2 (possibly prior versions) mailing-listx_transferred
- osvdb.org: 19969 vdb-entryx_transferred
- http://rgod.altervista.org/versatile100RC2.html x_transferred
- securityfocus.com: 15073 vdb-entryx_transferred
- secunia.com: 17174 third-party-advisoryx_transferred