4.3
CVSSv2

CVE-2008-3966

Published: 11/09/2008 Updated: 15/11/2008
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in MyBB (aka MyBulletinBoard) prior to 1.4.1 allow remote malicious users to inject arbitrary web script or HTML via (1) a certain referrer field in usercp2.php, (2) a certain location field in inc/functions_online.php, and certain (3) tsubject and (4) psubject fields in moderation.php.

Vulnerable Product Search on Vulmon Subscribe to Product

mybb mybb 1.2.0

mybb mybb 1.00

mybb mybb 1.2

mybb mybb 1.1.6

mybb mybb 1.1.8

mybb mybb 1.01

mybb mybb 1.04

mybb mybb 1.2.12

mybb mybb 1.2.10

mybb mybb 1.2.13

mybb mybb 1.1.7

mybb mybb 1.1.3

mybb mybb 1.02

mybb mybb 1.2.3

mybb mybb 1.2.4

mybb mybb 1.2.5

mybb mybb

mybb mybb 1.2.11

mybb mybb 1.2.6

mybb mybb 1.2.7

mybb mybb 1.1.2

mybb mybb 1.1.0

mybb mybb 1.2.1

mybb mybb 1.2.2

mybb mybb 1.2.9

mybb mybb 1.2.8

mybb mybb 1.1.4

mybb mybb 1.1.5

mybb mybb 1.03

mybb mybb 1.1.1