CVE-2008-3966: XSS
Multiple cross-site scripting (XSS) vulnerabilities in MyBB (aka MyBulletinBoard) before 1.4.1 allow remote attackers to inject arbitrary web script or HTML via (1) a certain referrer field in usercp2.php, (2) a certain location field in inc/functionsonline.php, and certain (3) tsubject and (4) psubject fields in moderation.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3966?
CVE-2008-3966 has a moderate severity rating as it can lead to cross-site scripting vulnerabilities.
How do I fix CVE-2008-3966?
To fix CVE-2008-3966, upgrade to MyBB version 1.4.1 or later to address the XSS vulnerabilities.
Which versions of MyBB are affected by CVE-2008-3966?
CVE-2008-3966 affects MyBB versions before 1.4.1, including versions 1.2.10 through 1.3.x.
Can CVE-2008-3966 be exploited remotely?
Yes, CVE-2008-3966 can be exploited remotely by attackers to inject arbitrary web scripts or HTML.
What type of vulnerability is CVE-2008-3966?
CVE-2008-3966 is categorized as a cross-site scripting (XSS) vulnerability.