Cross-site scripting (XSS) vulnerability in iforget.aspx in dotNetBB 2.42EC SP 3 and earlier allows remote attackers to inject arbitrary web script or HTML via the em parameter.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Dotnetbb_forums |
Dotnetbb |
* |
2.42ec_sp_3 (including) |
References