CVE-2007-1443 Information
Description
Multiple cross-site scripting (XSS) vulnerabilities in register.php in Woltlab Burning Board (wBB) 2.3.6 and Burning Board Lite 1.0.2pl3e allow remote attackers to inject arbitrary web script or HTML via the (1) r_username (2) r_email (3) r_password (4) r_confirmpassword (5) r_homepage (6) r_icq (7) r_aim (8) r_yim (9) r_msn (10) r_year (11) r_month (12) r_day (13) r_gender (14) r_signature (15) r_usertext (16) r_invisible (17) r_usecookies (18) r_admincanemail (19) r_emailnotify (20) r_notificationperpm (21) r_receivepm (22) r_emailonpm (23) r_pmpopup (24) r_showsignatures (25) r_showavatars (26) r_showimages (27) r_daysprune (28) r_umaxposts (29) r_dateformat (30) r_timeformat (31) r_startweek (32) r_timezoneoffset (33) r_usewysiwyg (34) r_styleid (35) r_langid (36) key_string (37) key_number (38) disablesmilies (39) disablebbcode (40) disableimages (41) field[1] (42) field[2] and (43) field[3] parameters. NOTE: a third-party researcher has disputed some of these vectors stating that only the r_dateformat and r_timeformat parameters in Burning Board 2.3.6 are affected.
Reference
http://secunia.com/advisories/24386 http://secunia.com/advisories/24404 http://securityreason.com/securityalert/2424 http://www.securityfocus.com/archive/1/461737/100/100/threaded http://www.securityfocus.com/archive/1/461744/100/100/threaded http://www.vupen.com/english/advisories/2007/0856
Share on: