|
Vulnerability Assessment & Network Security Forums |
|||||||||
If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important. If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery. Home >> Browse Vulnerability Assessment Database >> CGI abuses >> YaBB XSS and Administrator Command Execution Vulnerability Assessment Details
|
YaBB XSS and Administrator Command Execution |
||
Checks YaBB.pl XSS Detailed Explanation for this Vulnerability Assessment Summary : The remote web server contains a CGI application that suffers from multiple vulnerabilities. Description : The 'YaBB.pl' CGI is installed. This version is affected by a cross-site scripting vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input. As a result of this vulnerability, it is possible for a remote attacker to create a malicious link containing script code that will be executed in the browser of an unsuspecting user when followed. Another flaw in YaBB may permit a possible hacker to execute malicious administrative commands on the remote host by sending malformed IMG tags in posts to the remote YaBB forum and waiting for the forum administrator to view one of the posts. See also : http://archives.neohapsis.com/archives/bugtraq/2004-09/0227.html Solution : Unknown at this time. Network Security Threat Level: Medium / CVSS Base Score : 4 (AV:R/AC:L/Au:R/C:P/A:P/I:P/B:N) Networks Security ID: 11214, 11215 Vulnerability Assessment Copyright: This script is Copyright (C) 2004 David Maciejak |
||
Cables, Connectors |
SUN Blade X6250 Server 8GB RAM DUAL PROCESSORS 594-4531-01
$109.99
HP ProLiant BL460c G9 (Gen9) 2x E5-2670V3 12 Core 3.1GHz No Ram or No Drives
$59.98
Dell PowerEdge M620 0F9HJC Blade Server 2*E5-2670 2.60GHz 192GB RAM 2*300GB SAS
$103.99
Dell PowerEdge M640 Blade Server 2x Xeon Gold 5122 3.6GHz, No RAM, READ _
$401.04
Dell PowerEdge VRTX Rack Chassis 25-Bay 14.4TB HDD 2x M640 Blade 512GB RAM 2-Bay
$2335.00
DELL M630 BLADE SERVER x2 XEON E5-2660V3 @ 2.6GH H730 PERC HDD CADDIES 16GB FC
$50.00
HP ProLiant BL460c Server Blade (2 x CPU) 24GB RAM/No Drives
$45.60
Dell PowerEdge M1000E 16x Slots Blade Server W/ 8x Blade Server Blank Filler
$589.00
Dell PowerEdge M620 Blade Server
$39.99
Cisco UCS 5108 Blade Server Chassis Enclosure N20-C6508 4x PSU 8x Fans 2x Fabric
$139.99
|
||
No Discussions have been posted on this vulnerability. |