CVE-2006-1034: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Woltlab Burning Board (wBB) allow remote attackers to inject arbitrary web script or HTML via (1) the username parameter to galerieindex.php and possibly (2) galerieonfly.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. The second vector might not be XSS.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1034?
CVE-2006-1034 is considered a high severity vulnerability due to the potential for remote attackers to execute arbitrary web scripts.
How do I fix CVE-2006-1034?
To fix CVE-2006-1034, ensure you update Woltlab Burning Board to the latest patched version provided by the vendor.
Which versions of Woltlab Burning Board are affected by CVE-2006-1034?
CVE-2006-1034 affects Woltlab Burning Board versions 1.1.1, 2.0 Beta 3 and 4, 2.1.x, 2.2.2, 2.3.x, 2.4, 2.5, 2.6, and 2.7.
What types of attacks can exploit CVE-2006-1034?
CVE-2006-1034 allows attackers to exploit multiple cross-site scripting (XSS) vulnerabilities to inject malicious scripts.
Is CVE-2006-1034 mitigated by any configuration changes?
No, CVE-2006-1034 cannot be adequately mitigated by configuration changes; updating the software is essential to address the vulnerability.