Vulnerabilities > CVE-2006-4449 - HTML Injection vulnerability in Mybulletinboard 1.1.7

047910
CVSS 5.1 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
high complexity
mybulletinboard
exploit available

Summary

Cross-site scripting (XSS) vulnerability in attachment.php in MyBulletinBoard (MyBB) 1.1.7 and possibly other versions allows remote attackers to inject arbitrary web script or HTML via a GIF image that contains URL-encoded Javascript, which is rendered by Internet Explorer.

Vulnerable Configurations

Part Description Count
Application
Mybulletinboard
1

Exploit-Db

descriptionMyBB 1.1.7 Multiple HTML Injection Vulnerabilities. CVE-2006-4449 . Webapps exploit for php platform
idEDB-ID:28429
last seen2016-02-03
modified2006-08-26
published2006-08-26
reporterRedworm
sourcehttps://www.exploit-db.com/download/28429/
titleMyBB 1.1.7 - Multiple HTML Injection Vulnerabilities