Multiple vulnerabilities in XMB have been found, allowing attackers to exploit SQL injection vulnerabilities and cross site scripting issues.
Extreme Messageboard (XMB) is "a
very
popular and feature rich forum, based on PHP and MySQL".
XMB Partagium 1.8 SP2 is vulnerable but the XMB team fixed the bugs in record time and a new version is available for download.
"XMB Partagium 1.8 SP3 has now been made available to the public via the main XMB download area. All security vulnerabilities have now been patched."