CVE Vulnerabilities

CVE-2006-1282

Published: Mar 19, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

CRLF injection vulnerability in inc/function.php in MyBulletinBoard (MyBB) 1.04 allows remote attackers to conduct cross-site scripting (XSS), poison caches, or hijack pages via CRLF (%0A%0D) sequences in the Referrer HTTP header field, possibly when redirecting to other web pages.

Affected Software

NameVendorStart VersionEnd Version
MybulletinboardMybulletinboard1.0.1 (including)1.0.1 (including)
MybulletinboardMybulletinboard1.0.2 (including)1.0.2 (including)
MybulletinboardMybulletinboard1.0.3 (including)1.0.3 (including)
MybulletinboardMybulletinboard1.0.4 (including)1.0.4 (including)
MybulletinboardMybulletinboard1.0_final (including)1.0_final (including)
MybulletinboardMybulletinboard1.0_pr2 (including)1.0_pr2 (including)
MybulletinboardMybulletinboardrc1 (including)rc1 (including)
MybulletinboardMybulletinboardrc2 (including)rc2 (including)
MybulletinboardMybulletinboardrc3 (including)rc3 (including)
MybulletinboardMybulletinboardrc4 (including)rc4 (including)

References