4.3
CVSSv2

CVE-2006-1282

Published: 19/03/2006 Updated: 18/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

CRLF injection vulnerability in inc/function.php in MyBulletinBoard (MyBB) 1.04 allows remote malicious users to conduct cross-site scripting (XSS), poison caches, or hijack pages via CRLF (%0A%0D) sequences in the Referrer HTTP header field, possibly when redirecting to other web pages.

Vulnerable Product Search on Vulmon Subscribe to Product

mybulletinboard mybulletinboard 1.0.2

mybulletinboard mybulletinboard 1.0.3

mybulletinboard mybulletinboard rc4

mybulletinboard mybulletinboard 1.0.4

mybulletinboard mybulletinboard 1.0_final

mybulletinboard mybulletinboard 1.0_pr2

mybulletinboard mybulletinboard rc1

mybulletinboard mybulletinboard 1.0.1

mybulletinboard mybulletinboard rc2

mybulletinboard mybulletinboard rc3