vendor:
NovaBoard
by:
Pepelux
7.5
CVSS
HIGH
Cross-Site Scripting (XSS)
79
CWE
Product Name: NovaBoard
Affected Version From: 1.0.1
Affected Version To: 1.0.1
Patch Exists: NO
Related CWE: N/A
CPE: a:novaboard:novaboard
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: PHP & MySQL
2009
NovaBoard <= 1.0.1 / XSS Vulnerability
NovaBoard is a free, feature rich community message board software written in PHP & MySQL that allows you to set up your own forum within minutes. A vulnerability exists in the program which allows an attacker to inject malicious JavaScript code into the application. This can be done by sending a message to another user of the forum with the malicious code in the message body. Additionally, a non-persistent XSS attack can be performed by sending a malicious URL to the application. If an authenticated user visits the malicious URL, their username and password can be stolen.
Mitigation:
Ensure that all user-supplied input is properly sanitized and validated before being used in the application.