Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2006-2227

Overview

Vulnerability Score 4.3 4.3
CVE Id CVE-2006-2227
Last Modified 07 Mar 2011 09:35:34
Published 05 May 2006 03:02:00
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2006-2227

Summary

Cross-site scripting (XSS) vulnerability in misc.php in PunBB 1.2.11 allows remote attackers to inject arbitrary web script or HTML via the req_message parameter, because the value of the redirect_url parameter is not sanitized.

Vulnerable Systems

Application

  • Punbb 1.2.11


References

VUPEN - ADV-2006-1670

BUGTRAQ - 20060503 PunBB1.2.11 Cross-Site Scripting

SECUNIA - 19986

XF - punbb-misc-xss(26245)

BID - 17827

CONFIRM - http://www.punbb.org/download/hdiff/hdiff-1.2.11_to_1.2.12.html

CONFIRM - http://www.punbb.org/changelogs/1.2.11_to_1.2.12.txt

OSVDB - 25256

SREASON - 849


Last Updated: 27 May 2016 10:42:23