Multiple cross-site scripting (XSS) vulnerabilities in Datenbank MOD 2.7 and previous versions for Woltlab Burning Board allow remote malicious users to inject arbitrary web script or HTML via the fileid parameter to (1) info_db.php or (2) database.php.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
datenbank module datenbank module mod_2.7 |