Required CVE Record Information
Description
Multiple cross-site scripting (XSS) vulnerabilities in SKForum 1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) areaID parameter in area.View.action, (2) time parameter in planning.View.action, and (3) userID parameter in user.View.action.
References 8 Total
- securityfocus.com: 17389 vdb-entry
- osvdb.org: 24432 vdb-entry
- http://pridels0.blogspot.com/2006/04/skforum-xss-vuln.html
- secunia.com: 19484 third-party-advisory
- osvdb.org: 24430 vdb-entry
- osvdb.org: 24431 vdb-entry
- vupen.com: ADV-2006-1260 vdb-entry
- exchange.xforce.ibmcloud.com: skforum-multiple-xss(25641) vdb-entry
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 8 Total
- securityfocus.com: 17389 vdb-entryx_transferred
- osvdb.org: 24432 vdb-entryx_transferred
- http://pridels0.blogspot.com/2006/04/skforum-xss-vuln.html x_transferred
- secunia.com: 19484 third-party-advisoryx_transferred
- osvdb.org: 24430 vdb-entryx_transferred
- osvdb.org: 24431 vdb-entryx_transferred
- vupen.com: ADV-2006-1260 vdb-entryx_transferred
- exchange.xforce.ibmcloud.com: skforum-multiple-xss(25641) vdb-entryx_transferred