Vulnerability CVE-2006-2815


Published: 2006-06-05   Modified: 2012-02-12

Description:
Multiple cross-site scripting (XSS) vulnerabilities in Two Shoes M-Factory (TSMF) SimpleBoard 1.1.0 Stable (aka com_simpleboard), as used in Mambo and Joomla!, allow remote attackers to inject arbitrary web script or HTML via (1) the Name field in "post ne topic" in the Frontend, (2) the Title (aka Community-Title) field in Simpleboard Configuration in the Backend Admin Panel, and the (3) Name (aka Forum-Title) and (4) Name (aka Category-Title) fields in Simpleboard Administration in the Backend Admin Panel. NOTE: some sources have stated that the sb_authorname parameter is affected, but it is unclear which field is related to it.

See advisories in our WLB2 database:
Topic
Author
Date
Low
Joomla/Mambo CMS Component SimpleBoard 1.1 XSS-Vulnerabilities
Yannick von Arx
06.06.2006

Type:

CWE-79

(Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))

CVSS2 => (AV:N/AC:M/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.8/10
6.4/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Two shoes mambo factory -> Simpleboard 

 References:
http://lists.grok.org.uk/pipermail/full-disclosure/2006-June/046484.html
http://securityreason.com/securityalert/1030
http://www.securityfocus.com/archive/1/435615/100/0/threaded
http://www.securityfocus.com/bid/18251
http://www.vupen.com/english/advisories/2006/2111
https://exchange.xforce.ibmcloud.com/vulnerabilities/27021

Copyright 2024, cxsecurity.com

 

Back to Top