CVE-2005-0673: XSS
Cross-site scripting (XSS) vulnerability in usercpregister.php for phpBB 2.0.13 allows remote attackers to inject arbitrary web script or HTML by setting the (1) allowhtml, (2) allowbbcode, or (3) allowsmilies parameters to inject HTML into signatures for personal messages, possibly when they are processed by privmsg.php or viewtopic.php.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-0673?
CVE-2005-0673 is classified as a medium severity vulnerability due to its cross-site scripting (XSS) risk.
How do I fix CVE-2005-0673?
To fix CVE-2005-0673, users should upgrade phpBB to a patched version that addresses this vulnerability.
Who is affected by CVE-2005-0673?
CVE-2005-0673 affects users running phpBB version 2.0.13.
What type of attacks are possible with CVE-2005-0673?
Attackers can exploit CVE-2005-0673 to inject arbitrary web scripts or HTML into user signatures, compromising user data.
What can I do to protect my phpBB from CVE-2005-0673?
To protect against CVE-2005-0673, disable the allowhtml, allowbbcode, and allowsmilies options in the user settings until the software is updated.