CVE-2005-2161: XSS
Cross-site scripting (XSS) vulnerability in phpBB 2.0.16 allows remote attackers to inject arbitrary web script or HTML via nested [url] tags.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-2161?
CVE-2005-2161 is classified as a medium severity vulnerability due to its potential for unauthorized script execution impacting user sessions.
How do I fix CVE-2005-2161?
To fix CVE-2005-2161, upgrade phpBB to version 2.0.17 or later where the vulnerability is patched.
What is the exploit scenario for CVE-2005-2161?
The exploit scenario for CVE-2005-2161 involves an attacker crafting a malicious URL using nested [url] tags to execute arbitrary scripts in the context of another user's browser.
What applications are affected by CVE-2005-2161?
CVE-2005-2161 specifically affects phpBB version 2.0.16.
Are there any known mitigations for CVE-2005-2161?
The primary mitigation for CVE-2005-2161 is to ensure that phpBB is updated to the latest version, as it includes security patches addressing this vulnerability.