CVE-2006-1272: XSS
Published Mar 19, 2006
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in member.php in MyBulletin Board (MyBB) 1.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) aim, (2) yahoo, (3) msn, or (4) website field.
Affected Software
1 affected component
MyBulletinBoard MyBulletinBoard=1.0.3
Event History
Mar 19, 2006
CVE Published
02:02 AM
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1272?
The severity of CVE-2006-1272 is considered medium due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2006-1272?
To fix CVE-2006-1272, you should upgrade to a patched version of MyBulletin Board that addresses these XSS vulnerabilities.
3
What are the affected fields in CVE-2006-1272?
The affected fields in CVE-2006-1272 include aim, yahoo, msn, and website fields in the member.php file.
4
Can CVE-2006-1272 be exploited by remote attackers?
Yes, CVE-2006-1272 can be exploited by remote attackers to inject arbitrary web scripts or HTML.
5
Which version of MyBulletin Board is vulnerable to CVE-2006-1272?
MyBulletin Board version 1.0.3 is vulnerable to CVE-2006-1272.