First published: Wed Apr 25 2007(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in PunBB 1.2.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Referer HTTP header to misc.php or the (2) category name when deleting a category in admin_categories.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PunBB | <=1.2.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2235 has a medium severity rating due to its potential for exploitation via cross-site scripting.
To fix CVE-2007-2235, upgrade to PunBB version 1.3 or later, which addresses the XSS vulnerabilities.
Attack vectors for CVE-2007-2235 include injecting malicious scripts through the Referer HTTP header or by manipulating the category name during category deletion.
CVE-2007-2235 affects PunBB versions up to and including 1.2.14.
Yes, CVE-2007-2235 can be exploited remotely by attackers to execute arbitrary scripts on user browsers.