First published: Thu Jun 01 2006(Updated: )
Cross-site scripting (XSS) vulnerability in PunBB 1.2.11 allows remote authenticated administrators to inject arbitrary HTML or web script to other administrators via the "Admin note" feature, a different vulnerability than CVE-2006-2227.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PunBB | =1.2.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-2724 is classified as a cross-site scripting (XSS) vulnerability, which can potentially lead to data theft or account compromise.
To fix CVE-2006-2724, you should upgrade PunBB to a version that addresses this vulnerability.
CVE-2006-2724 affects remote authenticated administrators using PunBB version 1.2.11.
CVE-2006-2724 allows attackers to inject malicious scripts via the Admin note feature, compromising the security of other administrators.
CVE-2006-2724 is a different vulnerability than CVE-2006-2227, though both involve cross-site scripting in PunBB.