Vulnerabilities > CVE-2005-0741 - Remote UsersRecentPosts Cross-Site Scripting vulnerability in Yabb 2.0Rc1

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
yabb
nessus
exploit available

Summary

Cross-site scripting (XSS) vulnerability in YaBB.pl for YaBB 2.0 RC1 allows remote attackers to inject arbitrary web script or HTML via the username parameter in a usersrecentposts action.

Vulnerable Configurations

Part Description Count
Application
Yabb
1

Exploit-Db

descriptionYaBB 2.0 Remote UsersRecentPosts Cross-Site Scripting Vulnerability. CVE-2005-0741. Webapps exploit for php platform
idEDB-ID:25199
last seen2016-02-03
modified2005-03-08
published2005-03-08
reportertrueend5
sourcehttps://www.exploit-db.com/download/25199/
titleYaBB 2.0 - Remote UsersRecentPosts Cross-Site Scripting Vulnerability

Nessus

NASL familyCGI abuses : XSS
NASL idYABB_USERSRECENTPOSTS_XSS.NASL
descriptionThe installed version of YaBB (Yet Another Bulletin Board) on the remote host suffers from a remote cross-site scripting flaw due to its failure to properly sanitize input passed via the
last seen2020-06-01
modified2020-06-02
plugin id17305
published2005-03-10
reporterThis script is Copyright (C) 2005-2018 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/17305
titleYaBB YaBB.pl usersrecentposts Action username Parameter XSS