CVE-2007-1443: XSS
Multiple cross-site scripting (XSS) vulnerabilities in register.php in Woltlab Burning Board (wBB) 2.3.6 and Burning Board Lite 1.0.2pl3e allow remote attackers to inject arbitrary web script or HTML via the (1) rusername, (2) remail, (3) rpassword, (4) rconfirmpassword, (5) rhomepage, (6) ricq, (7) raim, (8) ryim, (9) rmsn, (10) ryear, (11) rmonth, (12) rday, (13) rgender, (14) rsignature, (15) rusertext, (16) rinvisible, (17) rusecookies, (18) radmincanemail, (19) remailnotify, (20) rnotificationperpm, (21) rreceivepm, (22) remailonpm, (23) rpmpopup, (24) rshowsignatures, (25) rshowavatars, (26) rshowimages, (27) rdaysprune, (28) rumaxposts, (29) rdateformat, (30) rtimeformat, (31) rstartweek, (32) rtimezoneoffset, (33) rusewysiwyg, (34) rstyleid, (35) rlangid, (36) keystring, (37) keynumber, (38) disablesmilies, (39) disablebbcode, (40) disableimages, (41) field[1], (42) field[2], and (43) field[3] parameters. NOTE: a third-party researcher has disputed some of these vectors, stating that only the rdateformat and rtimeformat parameters in Burning Board 2.3.6 are affected.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-1443?
CVE-2007-1443 is considered a moderate severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2007-1443?
To fix CVE-2007-1443, update to a patched version of Woltlab Burning Board or Burning Board Lite that addresses these vulnerabilities.
What software versions are affected by CVE-2007-1443?
CVE-2007-1443 affects Woltlab Burning Board version 2.3.6 and Woltlab Burning Board Lite version 1.0.2pl3e.
What types of vulnerabilities are present in CVE-2007-1443?
CVE-2007-1443 contains multiple cross-site scripting (XSS) vulnerabilities that allow remote code injection.
Who can exploit CVE-2007-1443?
CVE-2007-1443 can be exploited by remote attackers who can inject arbitrary web scripts or HTML via vulnerable input fields.