vendor:
Burning Board Forum Software
by:
SecurityFocus
7.5
CVSS
HIGH
Malicious Link Vulnerability
79
CWE
Product Name: Burning Board Forum Software
Affected Version From: Burning Board 1.0
Affected Version To: Burning Board 1.0
Patch Exists: YES
Related CWE: N/A
CPE: a:burning_board:burning_board:1.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Unix, Linux, Microsoft Windows
2002
Burning Board Forum Software Malicious Link Vulnerability
An attacker may allegedly create a malicious link which is capable of causing actions to be performed on the behalf of a legitimate Burning Board user who visits the link. To exploit this vulnerability, the attacker must manipulate URL parameters in the malicious link in such a way as to cause the desired actions to be performed by a user who visits the link. The legitimate forum user must also be authenticated via a cookie-based authentication credential. The malicious link may include BBCode.
Mitigation:
Ensure that all user input is properly validated and sanitized before being used in any application.