YaBB Image Upload HTML Injection Vulnerability
BID:15368
Info
YaBB Image Upload HTML Injection Vulnerability
| Bugtraq ID: | 15368 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 09 2005 12:00AM |
| Updated: | Nov 09 2005 12:00AM |
| Credit: | The discoverer of this vulnerability is currently unknown, the vendor disclosed this issue. |
| Vulnerable: |
YaBB YaBB 2.0 RC1 YaBB YaBB 2.0 RC2 YaBB YaBB 2.0 YaBB YaBB 1.41 YaBB YaBB 1.40 YaBB YaBB 1 Gold Release YaBB YaBB 1 Gold - SP 1.4 YaBB YaBB 1 Gold - SP 1.3.2 YaBB YaBB 1 Gold - SP 1.3.1 YaBB YaBB 1 Gold - SP 1.3 YaBB YaBB 1 Gold - SP 1.2 YaBB YaBB 1 Gold - SP 1 |
| Not Vulnerable: |
YaBB YaBB 2.1 |
Discussion
YaBB Image Upload HTML Injection Vulnerability
YaBB is prone to an HTML injection vulnerability. This is due to a lack of proper sanitization of user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.
This issue is only present when using the Microsoft Internet Explorer Web browser.
YaBB is prone to an HTML injection vulnerability. This is due to a lack of proper sanitization of user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would be executed in the context of the affected Web site, potentially allowing for theft of cookie-based authentication credentials. An attacker could also exploit this issue to control how the site is rendered to the user; other attacks are also possible.
This issue is only present when using the Microsoft Internet Explorer Web browser.
Exploit / POC
YaBB Image Upload HTML Injection Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
YaBB Image Upload HTML Injection Vulnerability
Solution:
The vendor has addressed this issue in the latest versions of the affected software. Users are advised to contact the vendor for the latest updates.
YaBB YaBB 1 Gold Release
YaBB YaBB 1 Gold - SP 1.3.2
YaBB YaBB 1 Gold - SP 1.3
YaBB YaBB 1 Gold - SP 1.3.1
YaBB YaBB 1 Gold - SP 1.4
YaBB YaBB 1 Gold - SP 1
YaBB YaBB 1 Gold - SP 1.2
YaBB YaBB 1.40
YaBB YaBB 1.41
YaBB YaBB 2.0 RC1
YaBB YaBB 2.0 RC2
YaBB YaBB 2.0
Solution:
The vendor has addressed this issue in the latest versions of the affected software. Users are advised to contact the vendor for the latest updates.
YaBB YaBB 1 Gold Release
-
YaBB YaBB_2.1.zip
http://www.yabbforum.com/downloads.php?file=YaBB_2.1.zip
YaBB YaBB 1 Gold - SP 1.3.2
-
YaBB YaBB_2.1.zip
http://www.yabbforum.com/downloads.php?file=YaBB_2.1.zip
YaBB YaBB 1 Gold - SP 1.3
-
YaBB YaBB_2.1.zip
http://www.yabbforum.com/downloads.php?file=YaBB_2.1.zip
YaBB YaBB 1 Gold - SP 1.3.1
-
YaBB YaBB_2.1.zip
http://www.yabbforum.com/downloads.php?file=YaBB_2.1.zip
YaBB YaBB 1 Gold - SP 1.4
-
YaBB YaBB_2.1.zip
http://www.yabbforum.com/downloads.php?file=YaBB_2.1.zip
YaBB YaBB 1 Gold - SP 1
-
YaBB YaBB_2.1.zip
http://www.yabbforum.com/downloads.php?file=YaBB_2.1.zip
YaBB YaBB 1 Gold - SP 1.2
-
YaBB YaBB_2.1.zip
http://www.yabbforum.com/downloads.php?file=YaBB_2.1.zip
YaBB YaBB 1.40
-
YaBB YaBB_2.1.zip
http://www.yabbforum.com/downloads.php?file=YaBB_2.1.zip
YaBB YaBB 1.41
-
YaBB YaBB_2.1.zip
http://www.yabbforum.com/downloads.php?file=YaBB_2.1.zip
YaBB YaBB 2.0 RC1
-
YaBB YaBB_2.1.zip
http://www.yabbforum.com/downloads.php?file=YaBB_2.1.zip
YaBB YaBB 2.0 RC2
-
YaBB YaBB_2.1.zip
http://www.yabbforum.com/downloads.php?file=YaBB_2.1.zip
YaBB YaBB 2.0
-
YaBB YaBB_2.1.zip
http://www.yabbforum.com/downloads.php?file=YaBB_2.1.zip
References
YaBB Image Upload HTML Injection Vulnerability
References:
References:
- Microsoft Internet Explorer 6.0 Embedded Content Cross Site Scripting (GIF) (securiteam.com)
- YaBB Downloads (YaBB)
- YaBB Homepage (YaBB)