OpenBB [IMG] tag cross-site scripting
| openbb-img-css (8278) |
Description:
OpenBB (Open Bulletin Board) is vulnerable to cross-site scripting. A remote attacker could post a malicious message containing JavaScript embedded within [IMG] tags, which would be executed in the victim's Web browser once the message is viewed.
An attacker could also exploit cross-site scripting vulnerabilities using OpenBB by creating a malicious URL link containing embedded script, which would be executed in the victim's Web browser in the security context of the hosting site, once the link is clicked.
Platforms Affected:
- Iansoft Enterprises, OpenBB 1.0.0 RC3 and prior
Remedy:
Apply the codeparse.php patch, as listed in the Open Bulletin Board Announcements Forum message dated 25-02-02 22:05:43. See References.
Consequences:
Other
References:
- BugTraq Mailing List, Mon Feb 25 2002 - 11:13:18 CST, Open Bulletin Board javascript bug. at http://archives.neohapsis.com/archives/bugtraq/2002-02/0272.html.
- Open Bulletin Board Announcements Forum 25-02-02 22:05:43, Important Security Fix at http://community.iansoft.net/read.php?TID=5159.
- Vuln-Dev Mailing List, 2002-05-23 19:31:05, Security holes in OpenBB at http://marc.theaimsgroup.com/?l=vuln-dev&m=102221487407632&w=2.
- BID-4171: OpenBB Image Tag Cross-Agent Scripting Vulnerability
- BID-4819: OpenBB BBCode Cross Agent HTML Injection Vulnerability
- BID-4824: OpenBB Cross-Site Scripting Vulnerability
- CVE-2002-0330: Cross-site scripting vulnerability in codeparse.php of Open Bulletin Board (OpenBB) 1.0.0 allows remote attackers to execute arbitrary script and steal cookies via Javascript in the IMG tag.
- CVE-2002-1829: Cross-site scripting (XSS) vulnerability in codeparse.php in Open Bulletin Board (OpenBB) 1.0.0 RC3 allows remote attackers to inject arbitrary web script or HTML via (1) myhome.php, (2) an onerror attribute in an IMG tag (a variant of CVE-2002-0330), or (3) a glow tag.
- OSVDB ID: 5658: OpenBB [IMG] and [glow] Tag XSS
Reported:
Feb 25, 2002
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
Copyright (c) 1994-2008 Internet Security Systems, Inc. All rights reserved worldwide.
For corrections or additions please email xforce@iss.net
