PT-2005-5021 · Binary Board System · Binary Board System
Published
2005-12-17
·
Updated
2008-09-20
·
CVE-2005-4333
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Binary Board System (BBS) versions 0.2.5 and earlier
Description
The issue allows remote attackers to inject arbitrary web script or HTML via specific parameters to various scripts. The vulnerable parameters include
inreplyto, article, and board to reply.pl, branch, board, and parameters to stats.pl, and board parameter to toc.pl.Recommendations
For Binary Board System (BBS) versions 0.2.5 and earlier, consider restricting access to the
reply.pl, stats.pl, and toc.pl scripts until a fix is available. As a temporary workaround, avoid using the inreplyto, article, board, branch, and other vulnerable parameters in the affected scripts.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Binary Board System