PT-2003-1731 · Infopop · Infopop Ultimate Bulletin Board
Antiacid
·
Published
2003-08-18
·
Updated
2016-10-18
·
CVE-2003-0587
CVSS v2.0
6.9
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Infopop Ultimate Bulletin Board (UBB) versions 6.x
Description:
The issue allows remote authenticated users to execute arbitrary web script and gain administrative access. This is achieved via the
displayed name attribute of the ubber cookie.Recommendations:
For Infopop Ultimate Bulletin Board (UBB) versions 6.x, update the software to a version that fixes this issue, ensuring that the
displayed name attribute of the ubber cookie is properly sanitized to prevent arbitrary web script execution.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Infopop Ultimate Bulletin Board