The avatar upload capability in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to execute arbitrary script by uploading files that include scripting code such as Javascript.
References
Link | Resource |
---|---|
http://securitytracker.com/id?1009935 | Vendor Advisory |
http://www.securityfocus.com/bid/10218 | Vendor Advisory |
http://secunia.com/advisories/11481 | Vendor Advisory |
http://marc.info/?l=bugtraq&m=108301983206107&w=2 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/15971 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2004-04-24 21:00
Updated : 2017-07-10 18:31
NVD link : CVE-2004-1969
Mitre link : CVE-2004-1969
JSON object : View
CWE
Products Affected
openbb
- openbb