CVE-2006-1324: XSS
Cross-site scripting (XSS) vulnerability in acp/lib/classdbmysql.php in Woltlab Burning Board (wBB) 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the errormsg parameter when a SQL error is generated.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1324?
CVE-2006-1324 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2006-1324?
To fix CVE-2006-1324, you should update your Woltlab Burning Board software to a version above 2.3.4 or apply patches provided by the vendor.
What kinds of attacks can be performed using CVE-2006-1324?
CVE-2006-1324 allows attackers to execute arbitrary web scripts or HTML in the context of the user's browser.
Which versions of Woltlab Burning Board are affected by CVE-2006-1324?
CVE-2006-1324 affects Woltlab Burning Board versions up to and including 2.3.4 and the 1.0.2pl2e_lite version.
Is CVE-2006-1324 a persistent vulnerability?
CVE-2006-1324 is not a persistent vulnerability; it is triggered during runtime when a SQL error occurs.