Multiple cross-site scripting (XSS) vulnerabilities in ThWboard Beta 2.8 and 2.81 allow remote attackers to inject arbitrary web script or HTML via (1) time in board.php, (2) the profile Homepage-Feld, (3) pictures, and (4) other "Diverse XSS Bugs."
Link | Tags |
---|---|
http://secunia.com/advisories/10120 | patch vendor advisory third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/13582 | vdb entry |
http://www.osvdb.org/4825 | patch vendor advisory vdb entry exploit |
http://sourceforge.net/project/shownotes.php?release_id=195009 | vendor advisory |
http://www.osvdb.org/4828 | patch vendor advisory vdb entry exploit |
http://www.securityfocus.com/bid/8959 | patch vdb entry |
http://www.osvdb.org/4829 | patch vendor advisory vdb entry exploit |
http://www.osvdb.org/4827 | patch vendor advisory vdb entry exploit |
http://www.osvdb.org/4826 | patch vendor advisory vdb entry exploit |
http://www.osvdb.org/3077 | patch vendor advisory vdb entry exploit |