OpenBB board.php FID Parameter XSS

medium Nessus Plugin ID 14822

Synopsis

A remote web application is vulnerable to A cross-site scripting attack.

Description

The remote host seems to be running OpenBB, a forum management system written in PHP.

The remote version of this software is vulnerable to cross-site scripting attacks, through the script 'board.php'.

Using a specially crafted URL, an attacker can cause arbitrary code execution for third-party users, thus resulting in a loss of integrity of their system.

Solution

Upgrade to the latest version of this software.

Plugin Details

Severity: Medium

ID: 14822

File Name: openbb_xss.nasl

Version: 1.24

Type: remote

Published: 9/27/2004

Updated: 1/19/2021

Configuration: Enable paranoid mode

Supported Sensors: Nessus

Vulnerability Information

Required KB Items: www/PHP, Settings/ParanoidReport

Excluded KB Items: Settings/disable_cgi_scanning

Exploit Available: true

Exploit Ease: No exploit is required

Vulnerability Publication Date: 12/28/2003

Reference Information

BID: 9303

CWE: 20, 442, 629, 711, 712, 722, 725, 74, 750, 751, 79, 800, 801, 809, 811, 864, 900, 928, 931, 990