UseBB BBcode Color Tag Code Injection Vulnerability
BID:14412
Info
UseBB BBcode Color Tag Code Injection Vulnerability
| Bugtraq ID: | 14412 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 20 2005 12:00AM |
| Updated: | Jul 20 2005 12:00AM |
| Credit: | Stefan Esser <[email protected]> is credited with the discovery of this vulnerability. |
| Vulnerable: |
UseBB UseBB 0.5.1 |
| Not Vulnerable: |
UseBB UseBB 0.5.1 a |
Discussion
UseBB BBcode Color Tag Code Injection Vulnerability
UseBB fails to properly sanitize BBCode '[color]' tags in message posts. This issue can be exploited to inject certain CSS (Cascading Style Sheet) code.
Exploitation of this vulnerability may allow an attacker to manipulate content or launch other attacks.
UseBB fails to properly sanitize BBCode '[color]' tags in message posts. This issue can be exploited to inject certain CSS (Cascading Style Sheet) code.
Exploitation of this vulnerability may allow an attacker to manipulate content or launch other attacks.
Exploit / POC
UseBB BBcode Color Tag Code Injection Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
UseBB BBcode Color Tag Code Injection Vulnerability
Solution:
The vendor has addressed this issue in UseBB version 0.5.1a and later:
UseBB UseBB 0.5.1
Solution:
The vendor has addressed this issue in UseBB version 0.5.1a and later:
UseBB UseBB 0.5.1
-
UseBB UseBB 0.5.1a
http://www.usebb.net/downloads/
References
UseBB BBcode Color Tag Code Injection Vulnerability
References:
References:
- Advisory 12/2005: UseBB Multiple Vulnerabilities (Hardened PHP Project)