vendor:
MegaBBS
by:
5.5
CVSS
MEDIUM
HTTP Response Splitting and SQL Injection
79, 89
CWE
Product Name: MegaBBS
Affected Version From: 2
Affected Version To: 2.1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
MegaBBS Multiple Vulnerabilities
MegaBBS is prone to multiple vulnerabilities due to insufficient sanitization of user-supplied data. These vulnerabilities can be exploited to carry out HTTP response splitting and SQL injection attacks.
Mitigation:
It is recommended to sanitize user-supplied data properly to prevent these vulnerabilities. Regularly updating to the latest version of MegaBBS is also advised.