First published: Mon Mar 24 2008(Updated: )
Cross-site scripting (XSS) vulnerability in PunBB 1.2.16 and earlier allows remote attackers to inject arbitrary web script or HTML via the get_host parameter to moderate.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PunBB | =1.2.3 | |
PunBB | =1.2.7 | |
PunBB | =1.0_beta2 | |
PunBB | =1.2.5 | |
PunBB | =1.2.10 | |
PunBB | =1.0 | |
PunBB | =1.2.1 | |
PunBB | =1.1.5 | |
PunBB | =1.1 | |
PunBB | =1.2.14 | |
PunBB | =1.2.13 | |
PunBB | =1.0.1 | |
PunBB | =1.1.1 | |
PunBB | =1.2.15 | |
PunBB | =1.0_beta3 | |
PunBB | =1.2.12 | |
PunBB | =1.0_rc1 | |
PunBB | =1.1.3 | |
PunBB | =1.0_rc2 | |
PunBB | =1.0_beta1 | |
PunBB | =1.2.4 | |
PunBB | =1.2.11 | |
PunBB | =1.2.8 | |
PunBB | =1.2.2 | |
PunBB | =1.2 | |
PunBB | =1.2.16 | |
PunBB | =1.1.4 | |
PunBB | =1.0_alpha | |
PunBB | =1.2.6 | |
PunBB | =1.1.2 | |
PunBB | =1.2.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-1485 is classified as a moderate severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2008-1485, you should upgrade PunBB to version 1.2.17 or later, which addresses the cross-site scripting issue.
CVE-2008-1485 affects PunBB versions 1.2.16 and earlier.
CVE-2008-1485 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary scripts.
Mitigation without upgrading is challenging, but you can implement input validation or web application firewalls to filter malicious input.