4.3

CVE-2006-1034

Exploit

Multiple cross-site scripting (XSS) vulnerabilities in Woltlab Burning Board (wBB) allow remote attackers to inject arbitrary web script or HTML via (1) the username parameter to galerie_index.php and possibly (2) galerie_onfly.php.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. The second vector might not be XSS.

Data is provided by the National Vulnerability Database (NVD)
WoltlabBurning Board Version1.1.1
WoltlabBurning Board Version2.0_beta_3
WoltlabBurning Board Version2.0_beta_4
WoltlabBurning Board Version2.0_beta_5
WoltlabBurning Board Version2.0_rc1
WoltlabBurning Board Version2.0_rc2
WoltlabBurning Board Version2.2.2
WoltlabBurning Board Version2.3.1
WoltlabBurning Board Version2.3.3
WoltlabBurning Board Version2.4
WoltlabBurning Board Version2.5
WoltlabBurning Board Version2.6
WoltlabBurning Board Version2.7
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.27% 0.473
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N