Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> CGI abuses : XSS >> Burning Board pms.php Cross-Site Scripting Vulnerability


Vulnerability Assessment Details

Burning Board pms.php Cross-Site Scripting Vulnerability

Vulnerability Assessment Summary
Checks for cross-site scripting vulnerability in Burning Board's pms.php script

Detailed Explanation for this Vulnerability Assessment

Summary :

The remote web server contains a PHP script which is vulnerable to a cross
site scripting vulnerability.

Description :

The version of Burning Board or Burning Board Lite installed on the
remote host may be prone to cross-site scripting attacks due to its
failure to properly sanitize input passed to the 'folderid' parameter
of the 'pms.php' script. A possible hacker may be able to exploit this flaw
to cause arbitrary HTML and script code to be run in a user's browser
within the context of the affected website.

See also :

http://www.securityfocus.com/archive/1/396858
http://www.woltlab.com/news/399_en.php

Solution :

Apply the security update referenced above.

Network Security Threat Level:

Low / CVSS Base Score : 3
(AV:R/AC:H/Au:NR/C:P/A:N/I:N/B:C)

Networks Security ID: 13353

Vulnerability Assessment Copyright: This script is Copyright (C) 2005 Tenable Network Security

Switch Components, Memory

Discussions

No Discussions have been posted on this vulnerability.