Cross-site request forgery (CSRF) vulnerabilities in (1) cp_forums.php, (2) cp_usergroup.php, (3) cp_ipbans.php, (4) myhome.php, (5) post.php, or (6) moderator.php in Open Bulletin Board (OpenBB) 1.0.6 and earlier allow remote attackers to execute arbitrary code by including the code in an image tag or a link.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=108301983206107&w=2 | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/15967 | third party advisory vdb entry |
http://secunia.com/advisories/11481 | vendor advisory broken link third party advisory exploit |
http://securitytracker.com/id?1009935 | vdb entry exploit vendor advisory broken link third party advisory |