PT-2005-3460 · Funkboard · Funkboard
Retrogod
·
Published
2005-08-16
·
Updated
2016-10-18
·
CVE-2005-2569
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
FunkBoard versions 0.66CF and earlier
Description
The issue allows remote attackers to inject arbitrary web script or HTML via certain parameters to various PHP files. This can be achieved by manipulating the
fbusername or fbpassword parameter in files such as editpost.php, prefs.php, newtopic.php, reply.php, or profile.php. Additionally, multiple parameters in register.php, including fbusername, fmail, www, icq, yim, location, sex, interебbies, sig, and aim, are vulnerable, as well as the subject parameter in newtopic.php.Recommendations
For FunkBoard versions 0.66CF and earlier, consider disabling the affected parameters, such as
fbusername, fbpassword, fmail, www, icq, yim, location, sex, interебbies, sig, aim, and subject, in the respective PHP files until a patch is available. Restrict access to the vulnerable PHP files, including editpost.php, prefs.php, newtopic.php, reply.php, profile.php, and register.php, to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Funkboard