First published: Wed Apr 12 2006(Updated: )
Cross-site scripting (XSS) vulnerability in XMB Forum 1.9.5 allows remote attackers to inject arbitrary web script or HTML by uploading a Flash (.SWF) video that contains a getURL function call, which causes the video to be rendered without disabling ActionScript.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
XMB Forum | =1.9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1748 is rated as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2006-1748, upgrade to a more secure version of XMB Forum that addresses this vulnerability.
CVE-2006-1748 is caused by the improper handling of Flash (.SWF) files in XMB Forum 1.9.5, allowing injection of malicious scripts.
CVE-2006-1748 affects users of XMB Forum version 1.9.5 and any sites using this software.
Potential impacts of CVE-2006-1748 include compromised user data through successful cross-site scripting attacks.