4.3
CVSSv2

CVE-2006-2755

Published: 02/06/2006 Updated: 18/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in index.php in UBBThreads 5.x and previous versions allows remote malicious users to inject arbitrary web script or HTML via the debug parameter, as demonstrated by stealing MD5 hashes of passwords.

Vulnerable Product Search on Vulmon Subscribe to Product

ubbcentral ubb.threads 5.0

ubbcentral ubb.threads 6.1.1

ubbcentral ubb.threads 6.2

ubbcentral ubb.threads 6.4.2

ubbcentral ubb.threads 6.4.3

ubbcentral ubb.threads 6.5.3

ubbcentral ubb.threads 5.5.1

ubbcentral ubb.threads 6.0

ubbcentral ubb.threads 6.2.1

ubbcentral ubb.threads 6.2.2

ubbcentral ubb.threads 6.4.4

ubbcentral ubb.threads 6.5

ubbcentral ubb.threads 6.0.3

ubbcentral ubb.threads 6.1

ubbcentral ubb.threads 6.4

ubbcentral ubb.threads 6.4.1

ubbcentral ubb.threads 6.5.2

ubbcentral ubb.threads 6.5.2_beta2

ubbcentral ubb.threads 6.0.1

ubbcentral ubb.threads 6.0.2

ubbcentral ubb.threads 6.2.3

ubbcentral ubb.threads 6.3

ubbcentral ubb.threads 6.3.1

ubbcentral ubb.threads 6.5.1

ubbcentral ubb.threads 6.5.1.1

Exploits

UBBThreads 5x,6x Multiple File Inclusion Vulnerabilities Contacts > ICQ: 10072 MSN/Mail: nukedx@nukedxcom web: wwwnukedxcom This exploits works on UBBThreads 5x,6x Original advisory can be found at: wwwnukedxcom/?viewdoc=40 Succesful exploitation register_globals on Version 6x GET -> [site]/[ubbpath]/includepollresults ...