Cross-site scripting (XSS) vulnerability in fce.php in UKiBoard 3.0.1 allows remote attackers to inject arbitrary web script or HTML via a BBCode url tag when using the show_post function. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information, some of which reference a source URL that appears to be for an unrelated issue.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/16912 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/24990 | vdb entry |