Total vulnerabilities in the database
Multiple cross-site scripting (XSS) vulnerabilities in the JGS-XA JGS-Gallery Addon 4.0.0 and earlier for Woltlab Burning Board (wBB) 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) userid parameter in (a) jgs_galerie_slideshow.php and (b) jgs_galerie_scroll.php, and the (2) katid parameter in (c) jgs_galerie_slideshow.php.
Software | From | Fixed in |
---|---|---|
woltlab / burning_board | 2.2.1 | 2.2.1.x |
woltlab / burning_board | 2.1.5 | 2.1.5.x |
woltlab / burning_board | 2.2.3 | 2.2.3.x |
woltlab / burning_board | 2.2.2 | 2.2.2.x |
woltlab / burning_board | 2.0 | 2.0.x |
woltlab / burning_board | 2.3.0 | 2.3.0.x |
woltlab / burning_board | 2.3.1 | 2.3.1.x |
woltlab / burning_board | 2.0.3 | 2.0.3.x |
jgs-xa / jgs-gallery_addon | 4.0 | 4.0.x |