CVE Vulnerabilities

CVE-2005-2564

Published: Aug 16, 2005 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Direct static code injection vulnerability in editcss.php in Gravity Board X (GBX) 1.1 allows remote attackers to execute arbitrary PHP code, HTML, and script via the csscontent parameter, which is directly inserted into the gbxfinal.css file.

Affected Software

Name Vendor Start Version End Version
Gravity_board_x Gravity_board_x_development_team 1.1 (including) 1.1 (including)

References