PT-2004-2864 · Openbb · Openbb

Published

2004-04-25

·

Updated

2024-02-08

·

CVE-2004-1967

CVSS v2.0
7.5
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P

Name of the Vulnerable Software and Affected Versions:

OpenBB versions 1.0.6 and earlier

Description:

The issue allows remote attackers to execute arbitrary code by including the code in an image tag or a link, due to cross-site request forgery (CSRF) vulnerabilities in several files, including `cp forums.php`, `cp usergroup.php`, `cp ipbans.php`, `myhome.php`, `post.php`, and `moderator.php`.

Recommendations:

For OpenBB versions 1.0.6 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

CSRF

Weakness Enumeration

Related Identifiers

CVE-2004-1967

Affected Products

Openbb