|
Family: CGI abuses --> Category: infos
YaBB XSS and Administrator Command Execution Vulnerability Scan
Vulnerability Scan Summary Checks YaBB.pl XSS
Detailed Explanation for this Vulnerability Test
Synopsis :
The remote web server contains a CGI application that suffers from
multiple vulnerabilities.
Description :
The 'YaBB.pl' CGI is installed. This version is affected by a
cross-site scripting vulnerability. This issue is due to a failure of
the application to properly sanitize user-supplied input.
As a result of this vulnerability, it is possible for a remote
attacker to create a malicious link containing script code that will
be executed in the browser of an unsuspecting user when followed.
Another flaw in YaBB may allow a possible hacker to execute malicious
administrative commands on the remote host by sending malformed IMG
tags in posts to the remote YaBB forum and waiting for the forum
administrator to view one of the posts.
See also :
http://archives.neohapsis.com/archives/bugtraq/2004-09/0227.html
Solution :
Unknown at this time.
Threat Level:
Medium / CVSS Base Score : 4
(AV:R/AC:L/Au:R/C:P/A:P/I:P/B:N)
Click HERE for more information and discussions on this network vulnerability scan.
|