Cross-site scripting (XSS) vulnerability in MyBulletinBoard (MyBB) allows remote attackers to inject arbitrary web script or HTML via a signature containing a JavaScript URI in the SRC attribute of an IMG element, in which the URI uses SGML numeric character references without trailing semicolons, as demonstrated by "javascript".
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://www.vupen.com/english/advisories/2006/0255 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/24225 | vdb entry |
http://www.securityfocus.com/bid/16308 | vdb entry |
http://archives.neohapsis.com/archives/bugtraq/2006-01/0332.html | mailing list exploit |
http://www.osvdb.org/22628 | vdb entry exploit |
http://secunia.com/advisories/18544 | exploit third party advisory patch vendor advisory |