Vulnerability Details CVE-2006-3761
Cross-site scripting (XSS) vulnerability in inc/functions_post.php in MyBB (aka MyBulletinBoard) 1.0 RC2 through 1.1.4 allows remote attackers to inject arbitrary web script or HTML via a javascript URI with an SGML numeric character reference in the url BBCode tag, as demonstrated using "javascript".
Exploit prediction scoring system (EPSS) score
EPSS Score 0.009
EPSS Ranking 74.1%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2006-3761
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.1
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.2
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.3
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.0.4
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.00_rc1
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.00_rc2
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.00_rc3
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.00_rc4
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.00_rc4_security_patch
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.01
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.04
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.0_final
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.0_pr2
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.0_preview_release_2
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.0_rc2
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.0_rc4
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.1
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.1.1
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.1.2
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.1.3
-
cpe:2.3:a:mybulletinboard:mybulletinboard:1.1.4