CVE-2006-0437 Information
Description
Cross-site scripting (XSS) vulnerability in admin_smilies.php in phpBB 2.0.19 allows remote attackers to inject arbitrary web script or HTML via Javascript events such as \onmouseover\ in the (1) smile_url or (2) smile_emotion parameters which bypasses a check for \ and \ characters.
Reference
http://lists.grok.org.uk/pipermail/full-disclosure/2006-February/041920.html
http://secunia.com/advisories/18693
http://securityreason.com/achievement_securityalert/31
http://securityreason.com/securityalert/406
http://www.osvdb.org/22928
http://www.vupen.com/english/advisories/2006/0445
https://exchange.xforce.ibmcloud.com/vulnerabilities/24497
Cross-site
scripting
(XSS)
vulnerability
in
admin_smilies.php
in
phpBB
2.0.19
allows
remote
attackers
to
inject
arbitrary
web
script
or
HTML
via
Javascript
events
such
as
\onmouseover
in
the
(1)
smile_url
or
(2)
smile_emotion
parameters
which
bypasses
a
check
for
\
and
\
characters.