CVE-2006-1215: XSS
Cross-site scripting (XSS) vulnerability in misc.php in Woltlab Burning Board (wBB) 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the percent parameter. NOTE: this issue has been disputed in a followup post, although the original disclosure might be related to reflected XSS.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1215?
The CVE-2006-1215 vulnerability is classified as a medium severity cross-site scripting (XSS) flaw.
How do I fix CVE-2006-1215?
To fix CVE-2006-1215, update Woltlab Burning Board to a version later than 2.3.4 that addresses this vulnerability.
What type of vulnerability is CVE-2006-1215?
CVE-2006-1215 is a cross-site scripting (XSS) vulnerability.
Which software is affected by CVE-2006-1215?
CVE-2006-1215 affects Woltlab Burning Board version 2.3.4.
Can CVE-2006-1215 lead to data theft?
Yes, CVE-2006-1215 can enable attackers to inject malicious scripts that may lead to data theft or session hijacking.