CVE Vulnerabilities

CVE-2004-1969

Published: Apr 25, 2004 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The avatar upload capability in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to execute arbitrary script by uploading files that include scripting code such as Javascript.

Affected Software

Name Vendor Start Version End Version
Openbb Openbb 1.0.0_beta1 1.0.0_beta1
Openbb Openbb 1.0.0_rc1 1.0.0_rc1
Openbb Openbb 1.0.0_rc2 1.0.0_rc2
Openbb Openbb 1.0.0_rc3 1.0.0_rc3
Openbb Openbb 1.0.5 1.0.5
Openbb Openbb 1.0.6 1.0.6

References