Rgboard 'bbs.lib.inc.php' Cross Site Scripting Vulnerability
BID:29230
Info
Rgboard 'bbs.lib.inc.php' Cross Site Scripting Vulnerability
| Bugtraq ID: | 29230 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-2296 CVE-2008-2295 |
| Remote: | Yes |
| Local: | No |
| Published: | May 14 2008 12:00AM |
| Updated: | Jul 05 2016 10:01PM |
| Credit: | e.wiZz |
| Vulnerable: |
Rgboard Rgboard 3.0.12 |
| Not Vulnerable: |
Rgboard Rgboard 4.0 |
Discussion
Rgboard 'bbs.lib.inc.php' Cross Site Scripting Vulnerability
Rgboard is prone to multiple input-validation vulnerabilities, including a cross-site script vulnerability and a remote file-include vulnerability.
An attacker may leverage these issues to execute arbitrary code within the context of the webserver process and steal cookie-based authentication credentials. Other attacks are also possible.
Rgboard 3.0.12 is vulnerable; other versions may also be affected.
Rgboard is prone to multiple input-validation vulnerabilities, including a cross-site script vulnerability and a remote file-include vulnerability.
An attacker may leverage these issues to execute arbitrary code within the context of the webserver process and steal cookie-based authentication credentials. Other attacks are also possible.
Rgboard 3.0.12 is vulnerable; other versions may also be affected.
Exploit / POC
Rgboard 'bbs.lib.inc.php' Cross Site Scripting Vulnerability
An attacker can exploit these issues through a browser. To exploit a cross-site scripting vulnerability, the attacker must entice an unsuspecting victim to follow a malicious URI:
The following proof-of-concept URI is available:
An attacker can exploit these issues through a browser. To exploit a cross-site scripting vulnerability, the attacker must entice an unsuspecting victim to follow a malicious URI:
The following proof-of-concept URI is available:
Solution / Fix
Rgboard 'bbs.lib.inc.php' Cross Site Scripting Vulnerability
Solution:
Reports indicate that Rgboard 4.0 addresses these issues. Please contact the vendor for information on how to obtain and apply this update.
Solution:
Reports indicate that Rgboard 4.0 addresses these issues. Please contact the vendor for information on how to obtain and apply this update.