CVE-2005-1290: XSS
Multiple cross-site scripting (XSS) vulnerabilities in phpBB 2.0.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) u parameter to profile.php, (2) highlight parameter to viewtopic.php, or (3) forumname or forumdesc parameters to adminforums.php.
Affected Software
Event History
Frequently Asked Questions
What are the XSS vulnerabilities in CVE-2005-1290?
CVE-2005-1290 identifies multiple cross-site scripting vulnerabilities in phpBB 2.0.14 and earlier versions, allowing attackers to inject arbitrary web scripts via specific parameters.
Which versions of phpBB are affected by CVE-2005-1290?
CVE-2005-1290 affects phpBB versions 2.0.0 through 2.0.14.
How can I mitigate CVE-2005-1290 vulnerabilities?
To mitigate CVE-2005-1290, upgrade phpBB to the latest version that addresses these XSS vulnerabilities.
What impact does CVE-2005-1290 have on phpBB installations?
The impact of CVE-2005-1290 includes the potential for remote attackers to execute unauthorized scripts, compromising the security of the phpBB installation.
Is there a patch available for CVE-2005-1290?
There is no individual patch for CVE-2005-1290; you must upgrade to a patched version of phpBB to resolve these vulnerabilities.