CVE-2006-0639: XSS
Published Feb 10, 2006
·Updated
Cross-site scripting (XSS) vulnerability in search.php in MyBB (aka MyBulletinBoard) 1.0.2 allows remote attackers with knowledge of the table prefix to inject arbitrary web script or HTML via a URL encoded value of the keywords parameter, as demonstrated by %3Cscript%3E.
Affected Software
1 affected component
MyBulletinBoard MyBulletinBoard=1.0.2
Remediation
Event History
Feb 10, 2006
CVE Published
11:02 AM
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-0639?
CVE-2006-0639 is classified as a medium severity cross-site scripting vulnerability.
2
How do I fix CVE-2006-0639?
To fix CVE-2006-0639, you should upgrade to a patched version of MyBB that addresses this vulnerability.
3
Who is affected by CVE-2006-0639?
Users of MyBB version 1.0.2 are affected by CVE-2006-0639.
4
What type of attack does CVE-2006-0639 enable?
CVE-2006-0639 enables remote attackers to inject arbitrary web scripts or HTML into a website.
5
What component is vulnerable in CVE-2006-0639?
The vulnerable component in CVE-2006-0639 is the search.php script within MyBB.