7.5
CVSSv2

CVE-2006-3420

Published: 07/07/2006 Updated: 20/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in editpost.php in MyBulletinBoard (MyBB) prior to 1.1.5 allows remote malicious users to perform unauthorized actions as a logged in user and delete arbitrary forum posts via a bbcode IMG tag with a modified delete parameter in a deletepost action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

mybulletinboard mybulletinboard 1.1

mybulletinboard mybulletinboard 1.1.2

mybulletinboard mybulletinboard 1.1.3

mybulletinboard mybulletinboard 1.1.4

mybulletinboard mybulletinboard 1.1.1