Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

CVE-2005-1193

EPSS 16.36% · P97

Public Exploits 1

ExploitDB · 1 EDB-25628 [webapps]
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2005-1193

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The bbencode_second_pass and make_clickable functions in bbcode.php for phpBB before 2.0.15, as used in viewtopic.php, privmsg.php, and other scripts, allow remote attackers to execute arbitrary script via a BBcode tag with a (1) javascript:, (2) applet:, (3) about:, (4) activex:, (5) chrome:, or (6) script: URI scheme, as demonstrated using the URL tag.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
PHPBB URL Tag BBCode.PHP漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
phpBB的2.0.15之前版本的bbcode.php中的bbencode_second_pass和make_clickable函数,当用于viewtopic.php、privmsg.php和其他脚本时,允许远程攻击者通过一个带有(1)javascript:,(2)applet:,(3)about:,(4)activex:,(5)chrome:或(6)script: URI 模式的BBcode标签来执行任意脚本,如使用URL标签。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2005-1193

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2005-1193

登录查看更多情报信息。

Vendor Advisories for CVE-2005-1193 (7)

Mailing List Discussions for CVE-2005-1193 (2)

Other References for CVE-2005-1193 (2)

Same Patch Batch · n/a · 2005-05-16 · 39 CVEs total

CVE-2005-1614Ultimate PHP Board ViewForum.PHP跨站脚本攻击漏洞
CVE-2005-1605Positive Software Corporation SiteStudio HTML注入漏洞
CVE-2005-1606Positive Software H-Sphere Winbox敏感Logfile内容泄露漏洞
CVE-2005-1607Remote Cart跨站脚本攻击(XSS)漏洞
CVE-2005-1608AutoTheme PostNuke Module多个未明漏洞
CVE-2005-1609Sun StorEdge 6130 Array未授权访问漏洞
CVE-2005-1610NukeET Base64 Codigo变量跨站脚本攻击漏洞
CVE-2005-1611WebCrossing WebX跨站脚本攻击漏洞
CVE-2005-1612OpenBB Read.PHP SQL注入漏洞
CVE-2005-1613OpenBB Member.PHP跨站脚本攻击漏洞
CVE-2005-1604PHP Advanced Transfer Manager任意文件上载漏洞
CVE-2005-1615Ultimate PHP Board ViewForum.PHP SQL注入漏洞
CVE-2005-1616Ultimate PHP Board 漏洞
CVE-2005-1617Willings WebCam和WebCam Lite 2.8漏洞
CVE-2005-1618雅虎通URL处理程序远程拒绝服务漏洞
CVE-2005-1619PHPMyChat跨站脚本攻击(XSS)漏洞
CVE-2005-1620Skull-Splitter Guestbook 跨站脚本攻击(XSS)漏洞
CVE-2005-1621PostNuke 目录遍历漏洞
CVE-2005-1622MetaCart e-Shop跨站脚本攻击(XSS)漏洞
CVE-2005-1595CodeThat.com CodeThatShoppingCart多个输入验证漏洞

Showing top 20 of 39 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2005-1193

No comments yet


Leave a comment