6.8
CVSSv2

CVE-2006-4157

Published: 16/08/2006 Updated: 17/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in index.php in Yet another Bulletin Board (YaBB) allows remote malicious users to inject arbitrary web script or HTML via the categories parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

yabb yabb 1.5.5b

yabb yabb 1.5.4

yabb yabb 1.5.5

yabb yabb 1.5.1

yabb yabb 1.5.2

Exploits

source: wwwsecurityfocuscom/bid/19460/info A cross-site scripting vulnerability affects YaBBSE because the application fails to properly sanitize user-supplied input before including it in dynamically generated web content An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user ...