4.3
CVSSv2

CVE-2006-0437

Published: 06/02/2006 Updated: 20/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in admin_smilies.php in phpBB 2.0.19 allows remote malicious users to inject arbitrary web script or HTML via Javascript events such as "onmouseover" in the (1) smile_url or (2) smile_emotion parameters, which bypasses a check for "<" and ">" characters.

Vulnerable Product Search on Vulmon Subscribe to Product

phpbb group phpbb 2.0.16

phpbb group phpbb 2.0.17

phpbb group phpbb 2.0.8a

phpbb group phpbb 2.0.9

phpbb group phpbb 2.0.14

phpbb group phpbb 2.0.15

phpbb group phpbb 2.0.7a

phpbb group phpbb 2.0.8

phpbb group phpbb 2.0.10

phpbb group phpbb 2.0.11

phpbb group phpbb 2.0.18

phpbb group phpbb 2.0.19

phpbb group phpbb 2.0.6c

phpbb group phpbb 2.0.12

phpbb group phpbb 2.0.13

phpbb group phpbb 2.0.6d

phpbb group phpbb 2.0.7

Exploits

phpBB 2019 suffers from several Cross Site Request Forgeries and XSS vulnerabilities Detailed exploitation provided ...