|
|
Info |
Last Modified |
| 6 months ago |
|
|
|
|
Description |
OpenBB contains a flaw that may allow a remote attacker to upload arbitrary files that can be executed on other client systems. The issue is due to the software not validating file types or content for avatar uloads. By uploading a script file instead of an image, an attacker can then post to the board with the malicious avatar. Subsequent viewers of the post will then execute the script in the context of their system.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Confidentiality,
Loss of Integrity
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
OSVDB:
Web Related
|
|
Solution |
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.
|
|
Products |
|
Open Bulletin Board
 |
1.0.2 |
1.0.3 |
1.0.4 |
1.0.5 |
1.0.6 |
1.0.1 |
|
|
|
|
Credit |
- Manuel Lopez - mantra
gulo.org -
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|