Multiple cross-site scripting (XSS) vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to inject arbitrary web script or HTML via the (1) Searchpage parameter to dosearch.php, (2) Number, (3) what, or (4) page parameter to newreply.php, (5) Number, (6) Board, or (7) what parameter to showprofile.php, (8) fpart or (9) page parameter to showflat.php, or (10) like parameter to showmembers.php.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2005-06-28T04:00:00

Updated: 2024-08-07T22:15:36.828Z

Reserved: 2005-06-29T00:00:00

Link: CVE-2005-2057

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2005-06-29T04:00:00.000

Modified: 2016-10-18T03:24:33.523

Link: CVE-2005-2057

cve-icon Redhat

No data.