CVE-2014-1840
Published Mar 3, 2014
Last updated 11 years ago
Overview
- Description
- Cross-site scripting (XSS) vulnerability in Upload/search.php in MyBB 1.6.12 and earlier allows remote attackers to inject arbitrary web script or HTML via the keywords parameter in a do_search action, which is not properly handled in a forced SQL error message.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-79
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:mybb:mybb:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6568D304-291D-4627-83BD-8859415CC666", "versionEndIncluding": "1.6.12" }, { "criteria": "cpe:2.3:a:mybb:mybb:1.6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E5B50C36-C3D7-48FD-805B-4A94E727C93F" }, { "criteria": "cpe:2.3:a:mybb:mybb:1.6.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FBEB75D4-FAA4-4A5B-AA0A-57EE8EE88E61" }, { "criteria": "cpe:2.3:a:mybb:mybb:1.6.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "00E51ABC-9F77-4028-BE47-D5BFD4FEC749" }, { "criteria": "cpe:2.3:a:mybb:mybb:1.6.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E0BD20D9-0DFC-451F-9C71-38C6D0236CF2" }, { "criteria": "cpe:2.3:a:mybb:mybb:1.6.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FDFE35CB-05CC-4E6F-B188-1141773E7F10" }, { "criteria": "cpe:2.3:a:mybb:mybb:1.6.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "22A90F66-DAE9-45FC-B255-390D569CCC56" }, { "criteria": "cpe:2.3:a:mybb:mybb:1.6.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E1A3FDDB-9488-405B-A2A0-500CF49061BE" }, { "criteria": "cpe:2.3:a:mybb:mybb:1.6.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "04264BC5-425C-47D4-9EE0-35BF11B904F9" }, { "criteria": "cpe:2.3:a:mybb:mybb:1.6.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5E42628F-7E7F-4E3A-BB8E-699166CB86B3" }, { "criteria": "cpe:2.3:a:mybb:mybb:1.6.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A02FA2FA-E035-40CD-9C0F-A143A931D40D" }, { "criteria": "cpe:2.3:a:mybb:mybb:1.6.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F52B8848-9103-4A78-A45B-6BE73855647A" }, { "criteria": "cpe:2.3:a:mybb:mybb:1.6.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C7170B92-1D43-49CA-BC79-469F0C8965D6" } ], "operator": "OR" } ] } ]