First published: Sat Dec 31 2005(Updated: )
Cross-site scripting (XSS) vulnerability in printthread.php in MyBB 1.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a thread message, which is not properly sanitized in the print view of the thread.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mybulletinboard | =1.0_rc4 | |
Mybulletinboard | =1.00_rc4 | |
Mybulletinboard | =rc3 | |
Mybulletinboard | =1.00_rc3 | |
Mybulletinboard | =rc2 | |
Mybulletinboard | =rc1 | |
Mybulletinboard | =1.00_rc4_security_patch | |
Mybulletinboard | =1.00_rc1 | |
Mybulletinboard | =rc4 | |
Mybulletinboard | =1.0_pr2 | |
Mybulletinboard | =1.00_rc2 | |
Mybulletinboard | =1.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-4603 has a moderate severity rating due to its potential for cross-site scripting attacks.
To fix CVE-2005-4603, upgrade to a version of MyBB later than 1.0.1 that addresses this XSS vulnerability.
CVE-2005-4603 affects MyBB 1.0.1 and earlier versions, including all release candidates before 1.0.1.
CVE-2005-4603 can be exploited through cross-site scripting (XSS), allowing attackers to inject malicious scripts into web pages.
You can determine if your MyBB installation is vulnerable by checking its version and comparing it to the affected versions list for CVE-2005-4603.