vendor:
UBB
by:
SecurityFocus
7.5
CVSS
HIGH
Cross-Agent Scripting
79
CWE
Product Name: UBB
Affected Version From: UBB
Affected Version To: UBB
Patch Exists: No
Related CWE: N/A
CPE: a:ubb:ubb
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Unix/Linux variants, Microsoft Windows NT/2000
2002
UBB Cross-Agent Scripting Vulnerability
UBB is prone to cross-agent scripting attacks via the insertion of HTML tags into image links in messages. Due to insufficient input validation, it is possible to insert arbitrary script code in forum messages/replies. The malicious script code will be executed in the browser of the user viewing the message, in the context of the site running UBB. This makes it possible for a malicious user to post a message which is capable of stealing another legitimate user's cookie-based authentication credentials.
Mitigation:
Input validation should be used to prevent malicious users from inserting arbitrary script code into messages.