First published: Sun Feb 19 2006(Updated: )
Cross-site scripting (XSS) vulnerability in u2u.php in XMB Forums 1.9.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter, as demonstrated using a URL-encoded iframe tag.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
XMB Forum | <=1.9.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0779 is classified as a medium severity cross-site scripting (XSS) vulnerability.
To fix CVE-2006-0779, upgrade to XMB Forums version 1.9.4 or later where this vulnerability is patched.
CVE-2006-0779 affects XMB Forums versions 1.9.3 and earlier.
CVE-2006-0779 allows attackers to execute cross-site scripting attacks by injecting arbitrary web scripts through the username parameter.
CVE-2006-0779 can lead to unauthorized actions on behalf of users or theft of sensitive information if exploited.