First published: Wed Nov 16 2005(Updated: )
Cross-site scripting (XSS) vulnerability in u2u.php in XMB 1.9.3 allows remote attackers to inject arbitrary web script or HTML via the username parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
XMB Forum | =1.9.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3544 has a medium severity level due to its potential impact on user sessions and information exposure.
To fix CVE-2005-3544, upgrade XMB to the latest version to ensure that the XSS vulnerability is patched.
The potential impacts of CVE-2005-3544 include unauthorized access to user accounts and the ability to execute malicious scripts on user browsers.
Users of XMB version 1.9.3 are affected by CVE-2005-3544, particularly those utilizing vulnerable configurations.
Yes, CVE-2005-3544 can be exploited remotely by attackers to inject malicious JavaScript or HTML through the affected parameter.