4.3
CVSSv2

CVE-2005-1008

Published: 02/05/2005 Updated: 05/09/2008
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in posts.asp for ASP-DEv XM Forum RC3 allows remote malicious users to inject arbitrary web script or HTML via a "javascript:" URL in an IMG tag.

Vulnerable Product Search on Vulmon Subscribe to Product

asp-dev xm forum rc3

Exploits

source: wwwsecurityfocuscom/bid/12958/info XM Forum is reported prone to a script injection vulnerability An attacker can supply arbitrary HTML and script code through the BBCode IMG tag to trigger this issue and execute arbitrary script code in a user's browser XM Forum RC3 is reported vulnerable It is possible that other versions a ...