CVE-2012-1604
medium
CVSS v3
โ
CVSS v4 NEW
โ
VIR risk
5.3
Description
Cross-site scripting (XSS) vulnerability in NextBBS 0.6 allows remote attackers to inject arbitrary web script or HTML via the do parameter to index.php.
Predictions
Exploit likelihood
20%
Patch ETA
โ
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Exploits
Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.
Exploit-DB
NextBBS 0.6 - 'index.php?do' Cross-Site Scripting
source: https://www.securityfocus.com/bid/52728/info
NextBBS is prone to multiple SQL-injection vulnerabilities, a cross-site scripting vulnerability, and an authentication-bypass vulnerability.
Exploiting these vulnerabilities could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, and bypass the authentication process to gain unauthorized access to the system.
NextBBS 0.6.0 is vulnerable; other versions may also be affected.
http://www.example.com/nextbbs.0.6.0/index.php?do=<body+onload=alert(document.cookie);>
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| nextbbs | nextbbs | 0.6 | |
References
- http://archives.neohapsis.com/archives/bugtraq/2012-03/0135.html
- http://packetstormsecurity.org/files/111250/NextBBS-0.6.0-Authentication-Bypass-SQL-Injection-XSS.html
- http://www.openwall.com/lists/oss-security/2012/03/29/8
- http://www.openwall.com/lists/oss-security/2012/03/30/2
- http://www.osvdb.org/80627
- http://www.securityfocus.com/bid/52728
- http://www.waraxe.us/advisory-80.html
- http://archives.neohapsis.com/archives/bugtraq/2012-03/0135.html
- http://packetstormsecurity.org/files/111250/NextBBS-0.6.0-Authentication-Bypass-SQL-Injection-XSS.html
- http://www.openwall.com/lists/oss-security/2012/03/29/8
- http://www.openwall.com/lists/oss-security/2012/03/30/2
- http://www.osvdb.org/80627
- http://www.securityfocus.com/bid/52728
- http://www.waraxe.us/advisory-80.html
CWEs
CWE-79
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.