CVE-2006-4707: XSS
Published Sep 12, 2006
·Updated
Cross-site scripting (XSS) vulnerability in admin/global.php (aka the Admin CP login form) in MyBB (aka MyBulletinBoard) 1.1.7 allows remote attackers to inject arbitrary web script or HTML via the query string ($SERVER[PHPSELF]).
Affected Software
1 affected component
MyBulletinBoard MyBulletinBoard=1.1.7
Remediation
Patch Available
Event History
Sep 12, 2006
CVE Published
04:07 PM
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-4707?
CVE-2006-4707 has a medium severity rating due to its potential to allow remote attackers to execute arbitrary scripts.
2
How do I fix CVE-2006-4707?
To fix CVE-2006-4707, it is recommended to upgrade MyBB to a version that is not affected by this vulnerability.
3
What software is affected by CVE-2006-4707?
CVE-2006-4707 specifically affects MyBB version 1.1.7.
4
What type of vulnerability is CVE-2006-4707?
CVE-2006-4707 is classified as a cross-site scripting (XSS) vulnerability.
5
Can CVE-2006-4707 be exploited by unauthenticated users?
Yes, CVE-2006-4707 can be exploited by unauthenticated users, allowing them to inject malicious scripts through the query string.