Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 526
Alerts This Week
Warning Icon 1 526

Gentoo: 200505-10 Normal: phpBB Cross-Site Scripting Issue

gentoo
Calendar Grey May 14, 2005
Scroller Gentoo
The phpBB platform running on Gentoo is vulnerable to XSS vulnerabilities that may allow for the execution of untrusted scripts. It is recommended to upgrade to mitigate these risks!
phpBB is vulnerable to a cross-site scripting attack that could allow arbitrary scripting code execution.

Summary

Gentoo Linux Security Advisory GLSA 200505-10 https://security.gentoo.org/ Severity: Normal Title: phpBB: Cross-Site Scripting Vulnerability Date: May 14, 2005 Bugs: #90213 ID: 200505-10

Synopsis ======= phpBB is vulnerable to a cross-site scripting attack that could allow arbitrary scripting code execution.
Background ========= phpBB is an Open Source bulletin board package.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-apps/phpBB < 2.0.15 >= 2.0.15
========== phpBB is vulnerable to a cross-site scripting vulnerability due to improper sanitization of user supplied input. Coupled with poor validation of BBCode URLs which may be included in a...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround