vendor:
SonicBB
by:
Unknown
5.5
CVSS
MEDIUM
Cross-Site Scripting
79
CWE
Product Name: SonicBB
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE: CVE-2007-5000
CPE: a:sonicbb:sonicbb:1.0
Metasploit:
https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2010-0602/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-CESA-2008-0006/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2008-0007/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-CESA-2008-0004/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-CESA-2008-0008/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2008-0004/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2008-0006/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2008-0008/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2008-0009/, https://www.rapid7.com/db/vulnerabilities/apache-httpd-cve-2007-5000/, https://www.rapid7.com/db/vulnerabilities/apache-httpd-2_2_x-mod_imagemap-xss-cve-2007-5000/, https://www.rapid7.com/db/vulnerabilities/apache-httpd-2_0_x-mod_imap-xss-cve-2007-5000/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2007-5000/, https://www.rapid7.com/db/vulnerabilities/f5-big-ip-cve-2007-5000/, https://www.rapid7.com/db/vulnerabilities/apache-httpd-2_0_x-mod_imagemap-xss-cve-2007-5000/, https://www.rapid7.com/db/vulnerabilities/http-apache-mod_imap-mod_imagemap-menu-xss/, https://www.rapid7.com/db/vulnerabilities/apple-osx-apache-cve-2007-5000/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-CESA-2008-0005/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2008-0005/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2008-0261/, https://www.rapid7.com/db/?q=CVE-2007-5000&type=&page=2, https://www.rapid7.com/db/?q=CVE-2007-5000&type=&page=2
Platforms Tested:
2007
Cross-Site Scripting Vulnerability in SonicBB
The SonicBB application fails to properly sanitize user-supplied input, leading to a cross-site scripting vulnerability. An attacker can exploit this vulnerability to execute arbitrary script code in the browser of a user visiting the affected site. This can be used to steal authentication credentials and launch further attacks.
Mitigation:
To mitigate this vulnerability, it is recommended to sanitize and validate user input before displaying it. Implementing a web application firewall (WAF) can also help in preventing XSS attacks.