VulnerabilityModified
CVE-2005-3688
Cross-site scripting (XSS) vulnerability in members.php in XMB 1.9.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the "Your Current Mood" field in the registration page.
MEDIUM 4.3EPSS 2.19%
Does this matter?
Lower severity and a low EPSS score (2.19%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in members.php in XMB 1.9.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the "Your Current Mood" field in the registration page.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 2.19% probability · 81th percentile
- CISA KEV
- Not listed
- Affected
- xmb forum/xmb
- Source
- cve@mitre.org
References
- http://irannetjob.com/content/view/163/28/Exploit, URL Repurposed
- http://secunia.com/advisories/17642Vendor Advisory
- http://securitytracker.com/id?1015237
- http://www.securityfocus.com/archive/1/417078/30/0/threaded
- http://www.securityfocus.com/bid/15489
- http://www.vupen.com/english/advisories/2005/2488
- https://docs.xmbforum2.com/index.php?title=Security_Issue_History
- http://irannetjob.com/content/view/163/28/Exploit, URL Repurposed
- http://secunia.com/advisories/17642Vendor Advisory
- http://securitytracker.com/id?1015237
- http://www.securityfocus.com/archive/1/417078/30/0/threaded
- http://www.securityfocus.com/bid/15489
- http://www.vupen.com/english/advisories/2005/2488
- https://docs.xmbforum2.com/index.php?title=Security_Issue_History
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.