CVE-2006-0063: XSS
Cross-site scripting (XSS) vulnerability in phpBB 2.0.19, when "Allowed HTML tags" is enabled, allows remote attackers to inject arbitrary web script or HTML via a permitted HTML tag with ' (single quote) characters and active attributes such as onmouseover, a variant of CVE-2005-4357.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0063?
CVE-2006-0063 has a high severity due to the potential for remote code execution and compromise of users' data through Cross-site scripting.
How do I fix CVE-2006-0063?
To fix CVE-2006-0063, upgrade to a more recent version of phpBB that does not have this vulnerability.
What systems are affected by CVE-2006-0063?
CVE-2006-0063 specifically affects phpBB version 2.0.19 when the 'Allowed HTML tags' feature is enabled.
What type of attack does CVE-2006-0063 enable?
CVE-2006-0063 enables attackers to exploit Cross-site scripting (XSS) vulnerabilities to inject arbitrary scripts.
Is CVE-2006-0063 related to other vulnerabilities?
Yes, CVE-2006-0063 is a variant of CVE-2005-4357, which also deals with Cross-site scripting issues.