| VID |
21755 |
| Severity |
30 |
| Port |
80, ... |
| Protocol |
TCP |
| Class |
CGI |
| Detailed Description |
The XMB Forum, according to its version number, has multiple input validation vulnerabilities. Extreme Message Board (XMB) Forum is a freely available web forum written in PHP. XMB Forum versions prior to 1.9.2 are vulnerable to multiple input validation vulnerabilities, which can be exploited by a remote attacker to conduct cross-site scripting and SQL injection attacks.
* Note: This check solely relied on the version number of XMB Forum installed on the remote Web server to assess this vulnerability, so this might be a false positive.
* References: http://forums.xmbforum.com/viewthread.php?tid=754523 http://marc.theaimsgroup.com/?l=bugtraq&m=112361545228809&w=2 http://securitytracker.com/alerts/2005/Mar/1013515.html
* Platforms Affected: XMB Group, XMB Forum versions prior to 1.9.2 Any operating system Any version |
| Recommendation |
Upgrade to the latest version of XMB (1.9.2 or later), available from the XMB Web site at http://www.xmbforum2.com/ |
| Related URL |
CVE-2005-0885,CVE-2005-2574,CVE-2005-2575 (CVE) |
| Related URL |
12886,14523 (SecurityFocus) |
| Related URL |
19814,19816 (ISS) |
|