First published: Tue Sep 12 2006(Updated: )
Cross-site scripting (XSS) vulnerability in inc/functions_post.php in MyBB (aka MyBulletinBoard) 1.1.7 allows remote attackers to inject arbitrary web script or HTML via a url BBCode tag that contains a javascript URI with an SGML numeric character reference and an embedded space, as demonstrated using "java& #115;cript," a different vulnerability than CVE-2006-3761.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mybulletinboard | =1.1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4706 is classified as a high severity vulnerability due to its ability to allow remote attackers to inject arbitrary web scripts or HTML.
To fix CVE-2006-4706, users should upgrade MyBB to version 1.1.8 or later, which addresses this XSS vulnerability.
CVE-2006-4706 is a cross-site scripting (XSS) vulnerability that affects MyBB 1.1.7.
CVE-2006-4706 specifically affects the functions_post.php file in MyBB.
CVE-2006-4706 can be exploited by remote attackers who can inject malicious scripts through a specific BBCode tag.