First published: Sat Nov 19 2005(Updated: )
Cross-site scripting (XSS) vulnerability in members.php in XMB 1.9.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the "Your Current Mood" field in the registration page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
XMB Forum | <=1.9.3 | |
XMB Forum | =1.8_sp1 | |
XMB Forum | =1.8_sp2 | |
XMB Forum | =1.8_sp3 | |
XMB Forum | =1.9.1 | |
XMB Forum | =1.9.2 | |
XMB Forum | =1.9_beta |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3688 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2005-3688, update XMB Forum to version 1.9.4 or later where the vulnerability is addressed.
CVE-2005-3688 affects users of XMB Forum versions 1.9.3 and earlier, as well as 1.8 SP1, SP2, SP3, and 1.9.1 and 1.9.2.
CVE-2005-3688 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject scripts.
Attackers exploiting CVE-2005-3688 can inject arbitrary web scripts or HTML, potentially compromising user data and security.