Cross-site scripting (XSS) vulnerability in iforget.aspx in dotNetBB 2.42EC SP 3 and earlier allows remote attackers to inject arbitrary web script or HTML via the em parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Dotnetbb_forums | Dotnetbb | * | 2.42ec_sp_3 (including) |