Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Syini666

#26945of 53,624
9.3Total CVSS
Vulnerabilities · 2
Medium
2
PT-2005-4529
4.3
2005-11-23
Mybb · Mybb · CVE-2005-3776
**Name of the Vulnerable Software and Affected Versions** MyBB version 1.0 PR2 Rev 686 **Description** The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML. The injection can occur via two main avenues: the subject field when creating a new thread and information passed to the Reputation system. **Recommendations** For MyBB version 1.0 PR2 Rev 686, as a temporary workaround, consider restricting user input in the subject field when creating new threads and limiting the information that can be passed to the Reputation system until a fix is available.
PT-2005-4530
5.0
2005-11-23
Mybulletinboard · Mybb · CVE-2005-3777
**Name of the Vulnerable Software and Affected Versions** MyBulletinBoard (MyBB) version 1.0 PR2 Rev 686 **Description** The issue allows remote attackers to delete or move private messages (PM) by modifying fields in the inbox form. **Recommendations** For MyBB version 1.0 PR2 Rev 686, as a temporary workaround, consider restricting access to the inbox form until a patch is available.