Required CVE Record Information
Description
Cross-site scripting (XSS) vulnerability in NBBC before 1.4.2 allows remote attackers to inject arbitrary web script or HTML via an invalid URL in a BBCode img tag.
References 6 Total
- secunia.com: 35520 third-party-advisory
- http://sourceforge.net/forum/message.php?msg_id=7455625
- http://sourceforge.net/forum/message.php?msg_id=7456208
- osvdb.org: 55266 vdb-entry
- exchange.xforce.ibmcloud.com: nbbc-img-xss(51288) vdb-entry
- http://sourceforge.net/tracker/?func=detail&aid=2809888&group_id=235382&atid=1096820
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 6 Total
- secunia.com: 35520 third-party-advisoryx_transferred
- http://sourceforge.net/forum/message.php?msg_id=7455625 x_transferred
- http://sourceforge.net/forum/message.php?msg_id=7456208 x_transferred
- osvdb.org: 55266 vdb-entryx_transferred
- exchange.xforce.ibmcloud.com: nbbc-img-xss(51288) vdb-entryx_transferred
- http://sourceforge.net/tracker/?func=detail&aid=2809888&group_id=235382&atid=1096820 x_transferred