CVE-2006-7076 Information

Description

Cross-site scripting (XSS) vulnerability in guestbook.php in Advanced Guestbook 2.4 for phpBB allows remote attackers to inject arbitrary web script or HTML via the entry parameter. NOTE: this issue might be resultant from SQL injection.

Reference

http://archives.neohapsis.com/archives/bugtraq/2006-07/0381.html http://secunia.com/advisories/19905 http://securityreason.com/securityalert/2323 http://www.majorsecurity.de/advisory/major_rls25.txt https://exchange.xforce.ibmcloud.com/vulnerabilities/27907

Share on: