Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2006-0495

Overview

Vulnerability Score 4.3 4.3
CVE Id CVE-2006-0495
Last Modified 05 Sep 2008 04:59:25
Published 31 Jan 2006 09:02:00
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2006-0495

Summary

Cross-site scripting (XSS) vulnerability in the Add Thread to Favorites feature in usercp2.php in MyBB (aka MyBulletinBoard) 1.02 allows remote attackers to inject arbitrary web script or HTML via an HTTP Referer header ($url variable).

Vulnerable Systems

Application

  • Mybulletinboard 1.0.2


References

XF - mybb-usercp2-xss(24392)

BID - 16419

BUGTRAQ - 20060129 MyBB 1.2 usercp2.php [ $url ] CrossSiteScripting ( XSS )


Last Updated: 27 May 2016 10:41:40