CVE Vulnerabilities

CVE-2006-3420

Published: Jul 07, 2006 | Modified: Jul 20, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Cross-site request forgery (CSRF) vulnerability in editpost.php in MyBulletinBoard (MyBB) before 1.1.5 allows remote attackers to perform unauthorized actions as a logged in user and delete arbitrary forum posts via a bbcode IMG tag with a modified delete parameter in a deletepost action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Affected Software

Name Vendor Start Version End Version
Mybulletinboard Mybulletinboard 1.1 (including) 1.1 (including)
Mybulletinboard Mybulletinboard 1.1.1 (including) 1.1.1 (including)
Mybulletinboard Mybulletinboard 1.1.2 (including) 1.1.2 (including)
Mybulletinboard Mybulletinboard 1.1.3 (including) 1.1.3 (including)
Mybulletinboard Mybulletinboard 1.1.4 (including) 1.1.4 (including)

References