CVE-2006-6459: XSS
Published Dec 11, 2006
·Updated
Cross-site scripting (XSS) vulnerability in toplist.php in PhpBB Toplist 1.3.7 allows remote attackers to inject arbitrary HTML or web script via the (1) Name and (2) Information fields when adding a new site (toplistnew action).
Affected Software
1 affected component
phpBB toplist=1.3.7
Event History
Dec 11, 2006
CVE Published
05:28 PM
Data Sourced
via NVD·05:28 PM
DescriptionSeverityAffected Software
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-6459?
CVE-2006-6459 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2006-6459?
To fix CVE-2006-6459, you should validate and sanitize input data from the Name and Information fields in toplist.php.
3
What type of attacks does CVE-2006-6459 enable?
CVE-2006-6459 enables attackers to perform cross-site scripting (XSS) attacks by injecting arbitrary HTML or web scripts.
4
Which software is affected by CVE-2006-6459?
CVE-2006-6459 affects PhpBB Toplist version 1.3.7.
5
What are the consequences of exploiting CVE-2006-6459?
Exploiting CVE-2006-6459 can lead to unauthorized actions on behalf of users, compromising user information and session integrity.