4.3
CVSSv2

CVE-2014-1840

Published: 03/03/2014 Updated: 04/03/2014
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Upload/search.php in MyBB 1.6.12 and previous versions allows remote malicious users to inject arbitrary web script or HTML via the keywords parameter in a do_search action, which is not properly handled in a forced SQL error message.

Vulnerable Product Search on Vulmon Subscribe to Product

mybb mybb 1.6.10

mybb mybb 1.6.2

mybb mybb 1.6.7

mybb mybb 1.6.9

mybb mybb

mybb mybb 1.6.0

mybb mybb 1.6.3

mybb mybb 1.6.4

mybb mybb 1.6.5

mybb mybb 1.6.6

mybb mybb 1.6.1

mybb mybb 1.6.11

mybb mybb 1.6.8

Exploits

MyBB version 1612 POST cross site scripting proof of concept code ...