First published: Wed Feb 13 2008(Updated: )
Cross-site scripting (XSS) vulnerability in sboxDB.php in Simple Machines Forum (SMF) Shoutbox 1.14 through 1.16b allows remote attackers to inject arbitrary web script or HTML via strings to the shoutbox form that start with "&#", contain the desired script, and end with ";".
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Simple Machines SMF Shoutbox | =1.15 | |
Simple Machines SMF Shoutbox | =1.14 | |
Simple Machines SMF Shoutbox | =1.16b |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0775 is considered a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
To mitigate CVE-2008-0775, update the Simple Machines Forum (SMF) Shoutbox to a secure version that addresses the XSS vulnerability.
CVE-2008-0775 affects users of Simple Machines Forum Shoutbox versions 1.14, 1.15, and 1.16b.
CVE-2008-0775 allows remote attackers to perform cross-site scripting (XSS) attacks by injecting arbitrary scripts via the shoutbox form.
Yes, users should look for updates or patches provided by Simple Machines for the affected versions to eliminate the vulnerability.