4.3
CVSSv2

CVE-2008-2024

Published: 30/04/2008 Updated: 29/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in index.php in miniBB 2.2, and possibly earlier, when register_globals is enabled, allows remote malicious users to inject arbitrary web script or HTML via the glang[] parameter in a registernew action.

Vulnerable Product Search on Vulmon Subscribe to Product

minibb minibb

Exploits

# Author: __GiReX__ # Homepage: girexaltervistaorg # Date: 21/04/2008 # CMS: miniBB 22 (and maybe prior) # Site: minibbnet # Bug 1: Full Path Disclosure # Bug 2: Cross Site Scripting # Bug 3: Remote SQL Injection # Need: register_globals = On --------------------------------------- # 21/04/2008 Vendor informed # 22/04/2008 miniBB 22a ...