CVE-2006-1717 Information

Description

Cross-site scripting (XSS) vulnerability in newthread.php in MyBB (aka MyBulletinBoard) 1.10 when configured to permit new threads by unregistered users allows remote attackers to inject arbitrary web script or HTML via the username.

Reference

http://secunia.com/advisories/19516 http://www.securityfocus.com/archive/1/430464/100/0/threaded http://www.securityfocus.com/bid/17427 https://exchange.xforce.ibmcloud.com/vulnerabilities/25730

Share on: