7.5
CVSSv2

CVE-2005-1193

Published: 16/05/2005 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The bbencode_second_pass and make_clickable functions in bbcode.php for phpBB prior to 2.0.15, as used in viewtopic.php, privmsg.php, and other scripts, allow remote malicious users to execute arbitrary script via a BBcode tag with a (1) javascript:, (2) applet:, (3) about:, (4) activex:, (5) chrome:, or (6) script: URI scheme, as demonstrated using the URL tag.

Vulnerable Product Search on Vulmon Subscribe to Product

phpbb group phpbb 2.0.14

phpbb group phpbb 2.0.2

phpbb group phpbb 2.0.7a

phpbb group phpbb 2.0.8

phpbb group phpbb 2.0_rc4

phpbb group phpbb 2.0.10

phpbb group phpbb 2.0.11

phpbb group phpbb 2.0.5

phpbb group phpbb 2.0.6

phpbb group phpbb 2.0.6c

phpbb group phpbb 2.0_beta1

phpbb group phpbb 2.0_rc1

phpbb group phpbb 2.0.12

phpbb group phpbb 2.0.13

phpbb group phpbb 2.0.6d

phpbb group phpbb 2.0.7

phpbb group phpbb 2.0_rc2

phpbb group phpbb 2.0_rc3

phpbb group phpbb 2.0.0

phpbb group phpbb 2.0.1

phpbb group phpbb 2.0.3

phpbb group phpbb 2.0.4

phpbb group phpbb 2.0.8a

phpbb group phpbb 2.0.9

Exploits

source: wwwsecurityfocuscom/bid/13545/info The phpbb vendor reports that a critical vulnerability exists in the BBCode handling routines of the 'bbcodephp' script The bbcode [url] tag is not properly sanitized of user-supplied input This could permit the injection of arbitrary HTML or script code into the browser of an unsuspecting us ...