CVE-2004-0322 Information

Description

Multiple cross-site scripting (XSS) vulnerabilities in XMB 1.8 Final SP2 allow remote attackers to execute arbitrary script as other users via the (1) member parameter in member.php (2) uid parameter in u2uadmin.php (3) user parameter in editprofile.php (4) an onmouseover event in an align tag when bbcode is allowed or (5) img tag where bbcode is allowed.

Reference

http://archives.neohapsis.com/archives/bugtraq/2004-02/0645.html http://marc.info/?l=bugtraq&m=107756526625179&w=2 http://www.securityfocus.com/bid/9726 http://www.xmbforum.com/community/boards/viewthread.php?tid=746859 https://exchange.xforce.ibmcloud.com/vulnerabilities/15292 https://exchange.xforce.ibmcloud.com/vulnerabilities/15294

Share on: