phpBB profile.php avatarselect...

- AV AC AU C I A
发布: 2004-03-22
修订: 2025-04-13

It has been reported that phpBB may be prone to a cross-site scripting vulnerability that may allow an attacker to execute arbitrary HTML or script code in a user's browser. The issue exists due to insufficient sanitization of user-supplied input via the 'avatarselect' form parameter of 'profile.php' script. phpBB 2.0.6d has been reported to be prone to this issue, however, other versions could be affected as well.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息