PT-2005-4810 · Ideal · Ideal Bb.Net

Published

2005-12-08

·

Updated

2017-07-20

·

CVE-2005-4078

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Ideal BB.NET versions 1.3 and earlier
Description The issue allows remote attackers to inject arbitrary web script or HTML via several parameters in different API endpoints, including the forumID, boardID, and topicRepeater1-p parameters in "topics.aspx", the boardID parameter in "categoryindex.aspx", the postID parameter in "posts.aspx", the catID parameter in "forums.aspx", and the memberID parameter in "member.aspx".
Recommendations For Ideal BB.NET versions 1.3 and earlier, as a temporary workaround, consider restricting access to the vulnerable parameters forumID, boardID, topicRepeater1-p, postID, catID, and memberID in their respective API endpoints until a patch is available. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-4078

Affected Products

Ideal Bb.Net