|
|
Vulnerability Assessment & Network Security Forums |
|||||||||
|
If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important. If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery. Home >> Browse Vulnerability Assessment Database >> CGI abuses >> YaBB XSS and Administrator Command Execution Vulnerability Assessment Details
|
YaBB XSS and Administrator Command Execution |
||
|
Checks YaBB.pl XSS Detailed Explanation for this Vulnerability Assessment Summary : The remote web server contains a CGI application that suffers from multiple vulnerabilities. Description : The 'YaBB.pl' CGI is installed. This version is affected by a cross-site scripting vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input. As a result of this vulnerability, it is possible for a remote attacker to create a malicious link containing script code that will be executed in the browser of an unsuspecting user when followed. Another flaw in YaBB may permit a possible hacker to execute malicious administrative commands on the remote host by sending malformed IMG tags in posts to the remote YaBB forum and waiting for the forum administrator to view one of the posts. See also : http://archives.neohapsis.com/archives/bugtraq/2004-09/0227.html Solution : Unknown at this time. Network Security Threat Level: Medium / CVSS Base Score : 4 (AV:R/AC:L/Au:R/C:P/A:P/I:P/B:N) Networks Security ID: 11214, 11215 Vulnerability Assessment Copyright: This script is Copyright (C) 2004 David Maciejak |
||
|
UPS, Power Protection, APC |
|
||
|
No Discussions have been posted on this vulnerability. |