First published: Mon Mar 15 2004(Updated: )
Cross-site scripting (XSS) vulnerability in YaBB 1 Gold(SP1.3) and YaBB SE 1.5.1 Final allows remote attackers to inject arbitrary web script via the background:url property in (1) glow or (2) shadow tags.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Simple Machines Forum | =1.0_b | |
Yabb | =1.5.1 | |
Yabb | =1_gold_-_sp_1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1827 is considered a moderate severity cross-site scripting (XSS) vulnerability.
To fix CVE-2004-1827, users should upgrade to the latest version of YaBB or implement input sanitization to mitigate XSS risks.
CVE-2004-1827 affects YaBB 1 Gold (SP1.3) and YaBB SE 1.5.1 Final, as well as certain versions of Simple Machines Forum.
CVE-2004-1827 is caused by improper handling of the background:url property in glow and shadow tags, allowing script injection.
Remote attackers can exploit CVE-2004-1827 to execute arbitrary web scripts in the context of the affected YaBB or SMF users.