Vulnerabilities > CVE-2007-1903 - Cross-Site Scripting vulnerability in Sonicbb 1.0

047910
CVSS 2.6 - LOW
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
high complexity
sonicbb
exploit available

Summary

Cross-site scripting (XSS) vulnerability in search.php in SonicBB 1.0 allows remote attackers to inject arbitrary web script or HTML via the part parameter. Successful exploitation requires that "magic_quotes_gpc" is disabled.

Vulnerable Configurations

Part Description Count
Application
Sonicbb
1

Exploit-Db

descriptionSonicBB 1.0 Search.PHP Cross-Site Scripting Vulnerability. CVE-2007-1903. Webapps exploit for php platform
idEDB-ID:30029
last seen2016-02-03
modified2007-05-14
published2007-05-14
reporterJesper Jurcenoks
sourcehttps://www.exploit-db.com/download/30029/
titleSonicBB 1.0 - Search.PHP Cross-Site Scripting Vulnerability

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/56724/sbb-xss.txt
idPACKETSTORM:56724
last seen2016-12-05
published2007-05-15
reporterJesper Jurcenoks
sourcehttps://packetstormsecurity.com/files/56724/sbb-xss.txt.html
titlesbb-xss.txt