Synopsis
The remote host is vulnerable to a Cross-Site Scripting (XSS) attack.
Description
The remote host is running ZeroBoard, a web-based bulletin board written in PHP. This version of Zeroboard is vulnerable to a cross-site scripting (XSS) flaw as well as a flaw in the 'preg_replace' function. An attacker exploiting
these flaws would require that the attacker be able to:
1) convince an unsuspecting user to visit a malicious website
2) send HTTP requests that are parsed by the 'preg_replace' function. Successful exploitation leads to arbitrary code execution on the remote system or arbitrary code executing in client browsers (after following a malicious URI).
Solution
Upgrade or patch according to vendor recommendations.
Plugin Details
Risk Information
Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N
Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Temporal Vector: CVSS:3.0/E:H/RL:U/RC:X
Vulnerability Information
CPE: cpe:/a:zeroboard:zeroboard