CVE-2006-0470: XSS
Cross-site scripting (XSS) vulnerability in search.php in MyBulletinBoard (MyBB) 1.02 allows remote attackers to inject arbitrary web script or HTML via the (1) sortby and (2) sortordr parameters, which are not properly handled in a redirection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-0470?
CVE-2006-0470 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2006-0470?
To fix CVE-2006-0470, you should upgrade MyBulletinBoard to a version that addresses this cross-site scripting vulnerability.
What are the affected versions for CVE-2006-0470?
CVE-2006-0470 affects MyBulletinBoard versions 1.0_final, 1.0_rc4, 1.0_pr2, 1.0.1, 1.0.2, 1.0_rc2, and 1.0_preview_release_2.
What type of vulnerability is CVE-2006-0470?
CVE-2006-0470 is a cross-site scripting (XSS) vulnerability.
Can CVE-2006-0470 lead to data theft?
Yes, successful exploitation of CVE-2006-0470 could allow attackers to execute scripts in the context of a victim's browser, potentially leading to data theft.