MyBulletinBoard Multiple HTML-Injection Vulnerabilities
BID:19740
Info
MyBulletinBoard Multiple HTML-Injection Vulnerabilities
| Bugtraq ID: | 19740 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 02 2006 12:00AM |
| Updated: | Sep 04 2006 06:48PM |
| Credit: | redworm is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
MyBulletinBoard MyBulletinBoard 1.1.7 MyBulletinBoard MyBulletinBoard 1.1.6 MyBulletinBoard MyBulletinBoard 1.1.5 MyBulletinBoard MyBulletinBoard 1.1.4 MyBulletinBoard MyBulletinBoard 1.1.3 MyBulletinBoard MyBulletinBoard 1.1.2 MyBulletinBoard MyBulletinBoard 1.1.1 MyBulletinBoard MyBulletinBoard 1.1 MyBulletinBoard MyBulletinBoard 1.0.4 MyBulletinBoard MyBulletinBoard 1.0.3 MyBulletinBoard MyBulletinBoard 1.0.2 MyBulletinBoard MyBulletinBoard 1.0.1 MyBulletinBoard MyBulletinBoard 1.0 PR2 MyBulletinBoard MyBulletinBoard 1.0 MyBulletinBoard MyBulletinBoard RC4 MyBulletinBoard MyBulletinBoard RC3 MyBulletinBoard MyBulletinBoard RC2 MyBulletinBoard MyBulletinBoard RC1 MyBulletinBoard MyBulletinBoard 1.2 MyBulletinBoard MyBulletinBoard 1.10 |
| Not Vulnerable: |
MyBulletinBoard MyBulletinBoard 1.1.8 |
Discussion
MyBulletinBoard Multiple HTML-Injection Vulnerabilities
MyBulletinBoard (or MyBB) is prone to multiple HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would execute in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
MyBulletinBoard 1.1.7 is vulnerable to these issues; other versions may also be affected.
MyBulletinBoard (or MyBB) is prone to multiple HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would execute in the context of the affected website, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
MyBulletinBoard 1.1.7 is vulnerable to these issues; other versions may also be affected.
Exploit / POC
MyBulletinBoard Multiple HTML-Injection Vulnerabilities
Attackers can exploit these issues through a web-client.
Attackers can exploit these issues through a web-client.
Solution / Fix
MyBulletinBoard Multiple HTML-Injection Vulnerabilities
Solution:
The vendor has released version 1.1.8 to address these issues. Please see the references for more information.
Solution:
The vendor has released version 1.1.8 to address these issues. Please see the references for more information.
References
MyBulletinBoard Multiple HTML-Injection Vulnerabilities
References:
References:
- MyBulletinBoard Home Page (MyBulletinBoard)