Summary
The remote host is missing an update to phpbb2
announced via advisory DSA 768-1.
A cross-site scripting vulnerability has been detected in phpBB2, a fully featured and skinneable flat webforum software, that allows remote attackers to inject arbitrary web script or HTML via nested tags.
The old stable distribution (woody) does not contain phpbb2.
Solution
For the stable distribution (sarge) this problem has been fixed in version 2.0.13-6sarge1.
For the unstable distribution (sid) this problem has been fixed in version 2.0.13-6sarge1.
We recommend that you upgrade your phpbb2 packages.
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20768-1
Severity
Classification
-
CVE CVE-2005-2161 -
CVSS Base Score: 4.3
AV:N/AC:M/Au:N/C:N/I:P/A:N
Related Vulnerabilities