Vulnerability Scanning Solutions, LLC.
Home
Our Process
Residential
Corporate
What We Scan For
Sample Report
Client List
Terms
Contact Us
What We Scan For
Family: Gentoo Local Security Checks --> Category: infos

[GLSA-200505-10] phpBB: Cross-Site Scripting Vulnerability Vulnerability Scan


Vulnerability Scan Summary
phpBB: Cross-Site Scripting Vulnerability

Detailed Explanation for this Vulnerability Test
The remote host is affected by the vulnerability described in GLSA-200505-10
(phpBB: Cross-Site Scripting Vulnerability)


phpBB is vulnerable to a cross-site scripting vulnerability due to
improper sanitization of user supplied input. Coupled with poor
validation of BBCode URLs which may be included in a forum post, an
unsuspecting user may follow a posted link triggering the
vulnerability.

Impact

Successful exploitation of the vulnerability could cause arbitrary
scripting code to be executed in the browser of a user.

Workaround

There are no known workarounds at this time.

References:
http://www.securityfocus.com/bid/13344/info/
http://securitytracker.com/id?1013918


Solution:
All phpBB users should upgrade to the latest version:
emerge --sync
emerge --ask --oneshot --verbose ">=www-apps/phpBB-2.0.15"


Threat Level: Medium


Click HERE for more information and discussions on this network vulnerability scan.

VSS, LLC.

P.O. Box 827051

Pembroke Pines, FL 33082-7051

Vulnerability Scanning Solutions, LLC.