CVE-2006-7076: XSS
Cross-site scripting (XSS) vulnerability in guestbook.php in Advanced Guestbook 2.4 for phpBB allows remote attackers to inject arbitrary web script or HTML via the entry parameter. NOTE: this issue might be resultant from SQL injection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-7076?
CVE-2006-7076 is considered to be a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2006-7076?
To fix CVE-2006-7076, it is recommended to upgrade to a version of Advanced Guestbook that is not affected by this vulnerability.
What type of vulnerability is CVE-2006-7076?
CVE-2006-7076 is a cross-site scripting (XSS) vulnerability that allows the injection of arbitrary web scripts or HTML.
What software is affected by CVE-2006-7076?
CVE-2006-7076 affects Advanced Guestbook version 2.4.0 for phpBB.
Who can exploit CVE-2006-7076?
Remote attackers can exploit CVE-2006-7076 to inject malicious scripts through the entry parameter of guestbook.php.