CVE-2006-1603: XSS
Cross-site scripting (XSS) vulnerability in profile.php in phpBB 2.0.19 allows remote attackers to inject arbitrary web script or HTML via the curpassword parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1603?
CVE-2006-1603 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2006-1603?
To fix CVE-2006-1603, it is recommended to upgrade phpBB to a version that is not affected by this vulnerability.
What systems are affected by CVE-2006-1603?
CVE-2006-1603 specifically affects phpBB version 2.0.19.
Can CVE-2006-1603 be exploited remotely?
Yes, CVE-2006-1603 can be exploited remotely through the profile.php page by injecting malicious scripts.
What are the potential impacts of exploiting CVE-2006-1603?
Exploiting CVE-2006-1603 can allow attackers to execute arbitrary web scripts in the context of the user's session.