7.5
CVSSv2

CVE-2005-1193

Published: 16/05/2005 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The bbencode_second_pass and make_clickable functions in bbcode.php for phpBB prior to 2.0.15, as used in viewtopic.php, privmsg.php, and other scripts, allow remote malicious users to execute arbitrary script via a BBcode tag with a (1) javascript:, (2) applet:, (3) about:, (4) activex:, (5) chrome:, or (6) script: URI scheme, as demonstrated using the URL tag.

Vulnerable Product Search on Vulmon Subscribe to Product

phpbb group phpbb 2.0.5

phpbb group phpbb 2.0.7a

phpbb group phpbb 2.0.8

phpbb group phpbb 2.0.11

phpbb group phpbb 2.0.1

phpbb group phpbb 2.0.13

phpbb group phpbb 2.0.3

phpbb group phpbb 2.0 rc2

phpbb group phpbb 2.0 rc1

phpbb group phpbb 2.0.4

phpbb group phpbb 2.0.12

phpbb group phpbb 2.0.9

phpbb group phpbb 2.0.7

phpbb group phpbb 2.0.8a

phpbb group phpbb 2.0.6d

phpbb group phpbb 2.0.2

phpbb group phpbb 2.0.14

phpbb group phpbb 2.0.10

phpbb group phpbb 2.0.6c

phpbb group phpbb 2.0 rc4

phpbb group phpbb 2.0.6

phpbb group phpbb 2.0.0

phpbb group phpbb 2.0 rc3

phpbb group phpbb 2.0 beta1

Exploits

source: wwwsecurityfocuscom/bid/13545/info The phpbb vendor reports that a critical vulnerability exists in the BBCode handling routines of the 'bbcodephp' script The bbcode [url] tag is not properly sanitized of user-supplied input This could permit the injection of arbitrary HTML or script code into the browser of an unsuspecting us ...