Cross-site scripting (XSS) vulnerability in usercp_register.php for phpBB 2.0.13 allows remote attackers to inject arbitrary web script or HTML by setting the (1) allowhtml, (2) allowbbcode, or (3) allowsmilies parameters to inject HTML into signatures for personal messages, possibly when they are processed by privmsg.php or viewtopic.php.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2005-03-07T05:00:00
Updated: 2005-05-25T09:00:00
Reserved: 2005-03-07T00:00:00
Link: CVE-2005-0673
JSON object: View
NVD Information
Status : Analyzed
Published: 2005-05-02T04:00:00.000
Modified: 2008-09-05T20:46:58.803
Link: CVE-2005-0673
JSON object: View
Redhat Information
No data.
CWE