PunBB Multiple Cross-Site Scripting Vulnerabilities
BID:30396
Info
PunBB Multiple Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 30396 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-3336 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 28 2008 12:00AM |
| Updated: | Jul 28 2008 08:07PM |
| Credit: | Dan Crowley |
| Vulnerable: |
PunBB PunBB 1.2.18 PunBB PunBB 1.2.17 PunBB PunBB 1.2.16 PunBB PunBB 1.2.15 PunBB PunBB 1.2.14 PunBB PunBB 1.2.13 PunBB PunBB 1.2.12 PunBB PunBB 1.2.11 PunBB PunBB 1.2.10 PunBB PunBB 1.2.10 PunBB PunBB 1.2.9 PunBB PunBB 1.2.8 PunBB PunBB 1.2.7 PunBB PunBB 1.2.6 PunBB PunBB 1.2.5 PunBB PunBB 1.2.4 PunBB PunBB 1.2.3 PunBB PunBB 1.2.2 PunBB PunBB 1.2.1 PunBB PunBB 1.1.5 PunBB PunBB 1.1.4 PunBB PunBB 1.1.3 PunBB PunBB 1.1.2 PunBB PunBB 1.1.1 PunBB PunBB 1.1 PunBB PunBB 1.0.1 PunBB PunBB 1.0 RC2 PunBB PunBB 1.0 RC1 PunBB PunBB 1.0 _beta3 PunBB PunBB 1.0 _beta2 PunBB PunBB 1.0 _beta1 PunBB PunBB 1.0 _alpha PunBB PunBB 1.0 |
| Not Vulnerable: |
PunBB PunBB 1.2.19 |
Discussion
PunBB Multiple Cross-Site Scripting Vulnerabilities
PunBB is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to PunBB 1.2.19 are vulnerable.
PunBB is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to PunBB 1.2.19 are vulnerable.
Exploit / POC
PunBB Multiple Cross-Site Scripting Vulnerabilities
Attackers can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
Attackers can exploit these issues by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
PunBB Multiple Cross-Site Scripting Vulnerabilities
Solution:
The vendor released PunBB 1.2.19 to address these issues. Please see the references for more information.
PunBB PunBB 1.0 RC1
PunBB PunBB 1.0
PunBB PunBB 1.0 _beta2
PunBB PunBB 1.0 RC2
PunBB PunBB 1.0 _beta3
PunBB PunBB 1.0 _alpha
PunBB PunBB 1.0 _beta1
PunBB PunBB 1.0.1
PunBB PunBB 1.1
PunBB PunBB 1.1.1
PunBB PunBB 1.1.2
PunBB PunBB 1.1.3
PunBB PunBB 1.1.4
PunBB PunBB 1.1.5
PunBB PunBB 1.2.1
PunBB PunBB 1.2.10
PunBB PunBB 1.2.10
PunBB PunBB 1.2.11
PunBB PunBB 1.2.12
PunBB PunBB 1.2.13
PunBB PunBB 1.2.14
PunBB PunBB 1.2.15
PunBB PunBB 1.2.16
PunBB PunBB 1.2.17
PunBB PunBB 1.2.18
PunBB PunBB 1.2.2
PunBB PunBB 1.2.3
PunBB PunBB 1.2.4
PunBB PunBB 1.2.5
PunBB PunBB 1.2.6
PunBB PunBB 1.2.7
PunBB PunBB 1.2.8
PunBB PunBB 1.2.9
Solution:
The vendor released PunBB 1.2.19 to address these issues. Please see the references for more information.
PunBB PunBB 1.0 RC1
-
PunBB punbb-1.2.19.tar.gz
http://punbb.informer.com/download/punbb-1.2.19.tar.gz
PunBB PunBB 1.0
-
PunBB punbb-1.2.19.tar.gz
http://punbb.informer.com/download/punbb-1.2.19.tar.gz
PunBB PunBB 1.0 _beta2
-
PunBB punbb-1.2.19.tar.gz
http://punbb.informer.com/download/punbb-1.2.19.tar.gz
PunBB PunBB 1.0 RC2
-
PunBB punbb-1.2.19.tar.gz
http://punbb.informer.com/download/punbb-1.2.19.tar.gz
PunBB PunBB 1.0 _beta3
-
PunBB punbb-1.2.19.tar.gz
http://punbb.informer.com/download/punbb-1.2.19.tar.gz
PunBB PunBB 1.0 _alpha
-
PunBB punbb-1.2.19.tar.gz
http://punbb.informer.com/download/punbb-1.2.19.tar.gz
PunBB PunBB 1.0 _beta1
-
PunBB punbb-1.2.19.tar.gz
http://punbb.informer.com/download/punbb-1.2.19.tar.gz
PunBB PunBB 1.0.1
-
PunBB punbb-1.2.19.tar.gz
http://punbb.informer.com/download/punbb-1.2.19.tar.gz
PunBB PunBB 1.1
-
PunBB punbb-1.2.19.tar.gz
http://punbb.informer.com/download/punbb-1.2.19.tar.gz
PunBB PunBB 1.1.1
-
PunBB punbb-1.2.19.tar.gz
http://punbb.informer.com/download/punbb-1.2.19.tar.gz
PunBB PunBB 1.1.2
-
PunBB punbb-1.2.19.tar.gz
http://punbb.informer.com/download/punbb-1.2.19.tar.gz
PunBB PunBB 1.1.3
-
PunBB punbb-1.2.19.tar.gz
http://punbb.informer.com/download/punbb-1.2.19.tar.gz
PunBB PunBB 1.1.4
-
PunBB punbb-1.2.19.tar.gz
http://punbb.informer.com/download/punbb-1.2.19.tar.gz
PunBB PunBB 1.1.5
-
PunBB punbb-1.2.19.tar.gz
http://punbb.informer.com/download/punbb-1.2.19.tar.gz
PunBB PunBB 1.2.1
-
PunBB punbb-1.2.19.tar.gz
http://punbb.informer.com/download/punbb-1.2.19.tar.gz
PunBB PunBB 1.2.10
-
PunBB punbb-1.2.19.tar.gz
http://punbb.informer.com/download/punbb-1.2.19.tar.gz
PunBB PunBB 1.2.10
-
PunBB punbb-1.2.19.tar.gz
http://punbb.informer.com/download/punbb-1.2.19.tar.gz
PunBB PunBB 1.2.11
-
PunBB punbb-1.2.19.tar.gz
http://punbb.informer.com/download/punbb-1.2.19.tar.gz
PunBB PunBB 1.2.12
-
PunBB punbb-1.2.19.tar.gz
http://punbb.informer.com/download/punbb-1.2.19.tar.gz
PunBB PunBB 1.2.13
-
PunBB punbb-1.2.19.tar.gz
http://punbb.informer.com/download/punbb-1.2.19.tar.gz
PunBB PunBB 1.2.14
-
PunBB punbb-1.2.19.tar.gz
http://punbb.informer.com/download/punbb-1.2.19.tar.gz
PunBB PunBB 1.2.15
-
PunBB punbb-1.2.19.tar.gz
http://punbb.informer.com/download/punbb-1.2.19.tar.gz
PunBB PunBB 1.2.16
-
PunBB punbb-1.2.19.tar.gz
http://punbb.informer.com/download/punbb-1.2.19.tar.gz
PunBB PunBB 1.2.17
-
PunBB punbb-1.2.19.tar.gz
http://punbb.informer.com/download/punbb-1.2.19.tar.gz
PunBB PunBB 1.2.18
-
PunBB punbb-1.2.19.tar.gz
http://punbb.informer.com/download/punbb-1.2.19.tar.gz
PunBB PunBB 1.2.2
-
PunBB punbb-1.2.19.tar.gz
http://punbb.informer.com/download/punbb-1.2.19.tar.gz
PunBB PunBB 1.2.3
-
PunBB punbb-1.2.19.tar.gz
http://punbb.informer.com/download/punbb-1.2.19.tar.gz
PunBB PunBB 1.2.4
-
PunBB punbb-1.2.19.tar.gz
http://punbb.informer.com/download/punbb-1.2.19.tar.gz
PunBB PunBB 1.2.5
-
PunBB punbb-1.2.19.tar.gz
http://punbb.informer.com/download/punbb-1.2.19.tar.gz
PunBB PunBB 1.2.6
-
PunBB punbb-1.2.19.tar.gz
http://punbb.informer.com/download/punbb-1.2.19.tar.gz
PunBB PunBB 1.2.7
-
PunBB punbb-1.2.19.tar.gz
http://punbb.informer.com/download/punbb-1.2.19.tar.gz
PunBB PunBB 1.2.8
-
PunBB punbb-1.2.19.tar.gz
http://punbb.informer.com/download/punbb-1.2.19.tar.gz
PunBB PunBB 1.2.9
-
PunBB punbb-1.2.19.tar.gz
http://punbb.informer.com/download/punbb-1.2.19.tar.gz
References
PunBB Multiple Cross-Site Scripting Vulnerabilities
References:
References:
- Changelog 1.2.17 to 1.2.19 (PunBB)
- PunBB Homepage (PunBB)