Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Stefan-Mybb

#30396of 53,635
8.6Total CVSS
Vulnerabilities · 2
Medium
2
PT-2014-3334
4.3
2014-01-10
Mybb · Mybb · CVE-2013-7288
**Name of the Vulnerable Software and Affected Versions** MyBB versions prior to 1.6.12 **Description** A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML. This is related to the handling of Yahoo video URLs in the mycode parse video function. **Recommendations** For versions prior to 1.6.12, update to version 1.6.12 or later to resolve the issue. As a temporary workaround, consider restricting the use of the mycode parse video function until a patch is available.
PT-2014-3324
4.3
2014-01-08
Mybb · Mybb · CVE-2013-7275
**Name of the Vulnerable Software and Affected Versions** MyBB versions prior to 1.6.12 **Description** A cross-site scripting issue allows remote attackers to inject arbitrary web script or HTML via the `editor` parameter in a smilie list popup. **Recommendations** For versions prior to 1.6.12, update to version 1.6.12 or later to resolve the issue.