CVE-2006-6421

Publication date 10 December 2006

Last updated 17 July 2025


Ubuntu priority

Description

Cross-site scripting (XSS) vulnerability in the private message box implementation (privmsg.php) in phpBB 2.0.x allows remote authenticated users to inject arbitrary web script or HTML via the "Message body" field in a message to a non-existent user.

Status

Package Ubuntu Release Status
phpbb2 9.10 karmic Not in release
9.04 jaunty Not in release
8.10 intrepid
Fixed 2.0.21-6
8.04 LTS hardy
Fixed 2.0.21-6
7.10 gutsy
Fixed 2.0.21-6
7.04 feisty
Fixed 2.0.21-6
6.10 edgy Ignored end of life, was needed
6.06 LTS dapper Ignored end of life