Multiple cross-site scripting (XSS) vulnerabilities in TextFileBB 1.0.16 allow remote attackers to inject arbitrary web script or HTML via Javascript events such as "onmouseover" in the (1) color, (2) size, or (3) url bbcode tags.
Link | Tags |
---|---|
http://securityreason.com/securityalert/828 | third party advisory |
http://securitytracker.com/id?1016013 | vdb entry |
http://www.securityfocus.com/bid/17750 | vdb entry exploit |
http://secunia.com/advisories/19883 | exploit third party advisory vendor advisory |
http://www.securityfocus.com/archive/1/432461/100/0/threaded | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/26129 | vdb entry |
http://www.osvdb.org/25123 | vdb entry |