4.3
CVSSv2

CVE-2012-4873

Published: 06/09/2012 Updated: 10/09/2012
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the file_download function in GNUBoard prior to 4.34.21 allows remote malicious users to inject arbitrary web script or HTML via the filename parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

sir gnuboard

Exploits

source: wwwsecurityfocuscom/bid/52622/info Gnuboard is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content Attacker-supplied HTML and script code would run in the context of the affected website, potentially allowing the attacker to steal coo ...