How to Buy
This script is Copyright (C) 2006-2015 Tenable Network Security, Inc.
The remote web server contains a Java application that is affected by
several cross-site scripting issues.
The remote host is running mvnForum, an open source, forum application
based on Java J2EE.
The version of mvnForum installed on the remote host fails to sanitize
user-supplied input to the 'activatecode' and 'member' parameters of
the 'activatemember' script before using it to generate dynamic web
content. Successful exploitation of this issue may lead to the
execution of arbitrary HTML and script code in a user's browser within
the context of the affected application.
See also :
Unknown at this time.
Risk factor :
Low / CVSS Base Score : 2.6
CVSS Temporal Score : 2.5
Public Exploit Available : true
Family: CGI abuses : XSS
Nessus Plugin ID: 21757 ()
Bugtraq ID: 18663
CVE ID: CVE-2006-3245
Get Nessus Professional to scan unlimited IPs, run compliance checks & more
The cookie settings on this website are set to 'allow all cookies' to give you the very best website experience. If you continue without changing these settings, you consent to this - but if you want, you can opt out of all cookies by clicking below.