Multiple cross-site scripting (XSS) vulnerabilities in AspBB 0.5.2 allow remote attackers to inject arbitrary web script or HTML via the (1) action parameter to default.asp or (2) get parameter to profile.asp.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Aspbb | Aspbb | 0.5.2 (including) | 0.5.2 (including) |