CVE Vulnerabilities

CVE-2006-1281

Published: Mar 19, 2006 | Modified: Oct 18, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.5 LOW
AV:N/AC:M/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Cross-site scripting (XSS) vulnerability in member.php in MyBulletinBoard (MyBB) 1.04 allows remote attackers to inject arbitrary web script or HTML via the url parameter, a different vulnerability than CVE-2006-1272. NOTE: 1.10 was later reported to be vulnerable.

Affected Software

Name Vendor Start Version End Version
Mybulletinboard Mybulletinboard 1.10 1.10
Mybulletinboard Mybulletinboard 1.0_final 1.0_final
Mybulletinboard Mybulletinboard rc3 rc3
Mybulletinboard Mybulletinboard rc2 rc2
Mybulletinboard Mybulletinboard rc1 rc1
Mybulletinboard Mybulletinboard 1.0.3 1.0.3
Mybulletinboard Mybulletinboard rc4 rc4
Mybulletinboard Mybulletinboard 1.0_pr2 1.0_pr2
Mybulletinboard Mybulletinboard 1.0.1 1.0.1
Mybulletinboard Mybulletinboard 1.0.4 1.0.4
Mybulletinboard Mybulletinboard 1.0.2 1.0.2

References