Korean
<< Back
VID 21755
Severity 30
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The XMB Forum, according to its version number, has multiple input validation vulnerabilities. Extreme Message Board (XMB) Forum is a freely available web forum written in PHP. XMB Forum versions prior to 1.9.2 are vulnerable to multiple input validation vulnerabilities, which can be exploited by a remote attacker to conduct cross-site scripting and SQL injection attacks.

* Note: This check solely relied on the version number of XMB Forum installed on the remote Web server to assess this vulnerability, so this might be a false positive.

* References:
http://forums.xmbforum.com/viewthread.php?tid=754523
http://marc.theaimsgroup.com/?l=bugtraq&m=112361545228809&w=2
http://securitytracker.com/alerts/2005/Mar/1013515.html

* Platforms Affected:
XMB Group, XMB Forum versions prior to 1.9.2
Any operating system Any version
Recommendation Upgrade to the latest version of XMB (1.9.2 or later), available from the XMB Web site at http://www.xmbforum2.com/
Related URL CVE-2005-0885,CVE-2005-2574,CVE-2005-2575 (CVE)
Related URL 12886,14523 (SecurityFocus)
Related URL 19814,19816 (ISS)