Synopsis
A remote web application is vulnerable to A cross-site scripting attack.
Description
The remote host seems to be running OpenBB, a forum management system written in PHP.
The remote version of this software is vulnerable to cross-site scripting attacks, through the script 'board.php'.
Using a specially crafted URL, an attacker can cause arbitrary code execution for third-party users, thus resulting in a loss of integrity of their system.
Solution
Upgrade to the latest version of this software.
Plugin Details
File Name: openbb_xss.nasl
Configuration: Enable paranoid mode
Supported Sensors: Nessus
Vulnerability Information
Required KB Items: www/PHP, Settings/ParanoidReport
Excluded KB Items: Settings/disable_cgi_scanning
Exploit Ease: No exploit is required
Vulnerability Publication Date: 12/28/2003
Reference Information
BID: 9303
CWE: 20, 442, 629, 711, 712, 722, 725, 74, 750, 751, 79, 800, 801, 809, 811, 864, 900, 928, 931, 990