MyBB 1.8.2 'usercp.php' HTML Injection Vulnerability
high Nessus Network Monitor Plugin ID 8619
Synopsis
The remote web server is running a PHP application which is outdated and thus prone to an HTML injection vulnerability.
Description
The remote web server hosts MyBulletinBoard, a web-based discussion board application. MyBB version 1.8.2 is prone to an HTML-injection vulnerability; other versions may also be affected. This is because it fails to sufficiently sanitize user-supplied input submitted to the 'usertitle' post parameter of the 'usercp.php' script. Attacker-supplied HTML or JavaScript code could run in the context of the affected site, compromising its contents or granting unauthorized access.