CVE-2005-0216: XSS
Published Feb 6, 2005
·Updated
Cross-site scripting (XSS) vulnerability in formmail.php in Woltlab Burning Board Lite 1.0.0, 1.0.1e, and possibly other versions, allows remote attackers to inject arbitrary web script and HTML via the userid parameter.
Affected Software
4 affected components
Woltlab Burning Board Lite=1.0.1e
Woltlab Burning Board Lite=1.0.0
Woltlab Burning Board Lite=1.0.0
Woltlab Burning Board Lite=1.0.1e
Event History
Feb 6, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0216?
CVE-2005-0216 has been classified as a medium severity cross-site scripting vulnerability.
2
How do I fix CVE-2005-0216?
To fix CVE-2005-0216, validate and sanitize the userid parameter in formmail.php to prevent script injection.
3
What versions are affected by CVE-2005-0216?
CVE-2005-0216 affects WoltLab Burning Board Lite versions 1.0.0 and 1.0.1e.
4
Can CVE-2005-0216 be exploited by remote attackers?
Yes, CVE-2005-0216 can be exploited by remote attackers to inject arbitrary scripts.
5
What should I do if I am using an affected version of WoltLab Burning Board Lite?
If using an affected version of WoltLab Burning Board Lite, upgrade to a patched version immediately to mitigate the risk.