PunBB 1.2.3 - Multiple HTML Injection Vulnerabilities

EDB-ID:

25230




Platform:

PHP

Date:

2005-03-16


source: https://www.securityfocus.com/bid/12828/info

PunBB is reportedly affected by multiple HTML injection vulnerabilities.

An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible such as the theft of cookie-based authentication credentials.

PunBB 1.2.3 is reported vulnerable, however, other versions may be affected as well. 

example@"/><script>alert()</script>.com