4.3
CVSSv2

CVE-2015-1431

Published: 10/02/2015 Updated: 08/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in includes/startup.php in phpBB prior to 3.0.13 allows remote malicious users to inject arbitrary web script or HTML via vectors related to "Relative Path Overwrite."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

phpbb phpbb

Vendor Advisories

Debian Bug report logs - #776699 phpbb3: CVE-2015-1431/CVE-2015-1432: CSRF and CSS injection Package: phpbb3; Maintainer for phpbb3 is phpBB packaging team <phpbb-l@listsa-eskwadraatnl>; Source for phpbb3 is src:phpbb3 (PTS, buildd, popcon) Reported by: Henri Salo <henri@nervfi> Date: Sat, 31 Jan 2015 12:36:01 UTC ...