Ultimate Bulletin Board [IMG] Tag Javascript Embedding Vulnerability

BID:2408

Info

Ultimate Bulletin Board [IMG] Tag Javascript Embedding Vulnerability

Bugtraq ID: 2408
Class: Input Validation Error
CVE:
Remote: No
Local: Yes
Published: Feb 21 2001 12:00AM
Updated: Feb 21 2001 12:00AM
Credit: This vulnerability was announced to Bugtraq by Scott Ashman <[email protected]> on February 21, 2001.
Vulnerable: Infopop Ultimate Bulletin Board 5.0 .x Beta
- BSDI BSD/OS 4.0.1
- Debian Linux 2.2
- HP HP-UX 11.11
- OpenBSD OpenBSD 2.8
- Redhat Linux 7.0
- SCO eServer 2.3
- Sun Solaris 8_sparc
Not Vulnerable:

Discussion

Ultimate Bulletin Board [IMG] Tag Javascript Embedding Vulnerability

Ultimate Bulletin Board is a free software package available from Infopop. The UBB package is a web based bulletin board package designed to offer discussion forums from a web interface.

A problem with a beta version of the software could allow the retrieval of user cookies. Upon logging into the UBB, cookies containing user information are stored on the users drive. These cookies normally contain sensitive information, such as the login name and password. Due to the insufficient checking of input by the bulletin board, it is possible to embed a single line of javascript between the [img] tags and post the code to the bulletin board. Upon replying to the message, a users browser would then interpret and execute the javascript, sending the information to a remote site. The problem can be exploited while the HTML bulletin board post option is turned off.

This makes it possible for a user with malicious motives to post a message to the bulletin board containing malicious code, and retrieve the users cookie.

Exploit / POC

Ultimate Bulletin Board [IMG] Tag Javascript Embedding Vulnerability

Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.

Solution / Fix

Ultimate Bulletin Board [IMG] Tag Javascript Embedding Vulnerability

Solution:
Upgrades available:


Infopop Ultimate Bulletin Board 5.0 .x Beta

References

Ultimate Bulletin Board [IMG] Tag Javascript Embedding Vulnerability

References:
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report