CVE-2004-0730: XSS
Multiple cross-site scripting (XSS) vulnerabilities in PhpBB 2.0.8 allow remote attackers to inject arbitrary web script or HTML via (1) the cattitle parameter in index.php, (2) the faq[0][0] parameter in langfaq.php as accessible from faq.php, or (3) the faq[0][0] parameter in langbbcode.php as accessible from faq.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0730?
CVE-2004-0730 has been classified as a medium severity vulnerability due to the potential for cross-site scripting attacks.
How do I fix CVE-2004-0730?
To fix CVE-2004-0730, it is recommended to upgrade PhpBB to version 2.0.9 or later, which addresses these vulnerabilities.
What types of attacks are possible with CVE-2004-0730?
CVE-2004-0730 allows remote attackers to execute arbitrary web scripts or HTML, leading to potential phishing or cookie theft.
Which versions of PhpBB are affected by CVE-2004-0730?
CVE-2004-0730 affects PhpBB versions 2.0.8 and 2.0.8a.
How can I determine if my PhpBB installation is vulnerable to CVE-2004-0730?
You can determine if your PhpBB installation is vulnerable by checking the version number against the affected versions listed for CVE-2004-0730.