Multiple cross-site scripting (XSS) vulnerabilities in Photo Album 2.0.53 module for phpBB allow remote attackers to inject arbitrary web script or HTML via the bsid parameter to (1) album_cat.php or (2) album_comment.php.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/13157 | vdb entry exploit |
http://www.digitalparadox.org/advisories/phpbbp.txt | |
http://marc.info/?l=bugtraq&m=111343406309969&w=2 | mailing list |
http://www.securityfocus.com/bid/13158 | vdb entry exploit |