Synopsis
The remote web server contains a script that is vulnerable to a SQL injection attack.
Description
The remote host is running MercuryBoard, a web-based Message board
written in PHP.
This version of MercuryBoard is vulnerable to a Cross-Site Scripting (XSS)
attack
An attacker exploiting this flaw would need to be able to convince
an unsuspecting user to visit a malicious website. Upon
successful exploitation, the attacker would be able to possibly
steal credentials or execute browser-side code.
In addition, the remote host is vulnerable to a SQL Injection attack. An attacker exploiting this flaw would be able to read data, modify data, or execute commands.
Solution
Upgrade to version 1.1.3 or higher.
Plugin Details
Risk Information
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C
Vulnerability Information
CPE: cpe:/a:mercuryboard:mercuryboard_message_board