NanoBB Cross Site Scripting and Multiple SQL Injection Vulnerabilities
BID:60451
Info
NanoBB Cross Site Scripting and Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 60451 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 10 2013 12:00AM |
| Updated: | Jun 10 2013 12:00AM |
| Credit: | CWH Underground |
| Vulnerable: |
amrit Nanobb 0.7 |
| Not Vulnerable: | |
Discussion
NanoBB Cross Site Scripting and Multiple SQL Injection Vulnerabilities
NanoBB is prone to a cross-site scripting vulnerability and multiple SQL-injection vulnerabilities.
Exploiting these vulnerabilities could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
NanoBB 0.7 is vulnerable; other versions may also be affected.
NanoBB is prone to a cross-site scripting vulnerability and multiple SQL-injection vulnerabilities.
Exploiting these vulnerabilities could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
NanoBB 0.7 is vulnerable; other versions may also be affected.