Cross-site scripting (XSS) vulnerability in search.php in MyBulletinBoard (MyBB) 1.02 allows remote attackers to inject arbitrary web script or HTML via the (1) sortby and (2) sortordr parameters, which are not properly handled in a redirection.
Link | Tags |
---|---|
http://community.mybboard.net/attachment.php?aid=2181 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/24466 | vdb entry |
http://seclists.org/lists/bugtraq/2006/Jan/0414.html | vendor advisory mailing list exploit |
http://www.securityfocus.com/bid/16387 | vdb entry |
http://community.mybboard.net/showthread.php?tid=6418 | |
http://www.vupen.com/english/advisories/2006/0350 | vdb entry |
http://secunia.com/advisories/18617 | third party advisory vendor advisory |
http://securityreason.com/securityalert/374 | third party advisory |
http://www.osvdb.org/22750 | vdb entry |