CVE-2013-5020
Description
Multiple cross-site scripting (XSS) vulnerabilities in bb_admin.php in MiniBB before 3.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) forum_name, (2) forum_group, (3) forum_icon, or (4) forum_desc parameter. NOTE: the whatus vector is already covered by CVE-2008-2066.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Exploits
Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.
Exploit-DB
WordPress Plugin miniBB - SQL Injection / Multiple Cross-Site Scripting Vulnerabilities
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| minibb | minibb | {"endIncluding":"3.0"} | |
References
- http://osvdb.org/95122
- http://seclists.org/fulldisclosure/2013/Jul/102
- http://www.minibb.com/download.php?file=minibb_update
- http://www.minibb.com/forums/news-9/minibb-3.0.1-released-stable-fixed-secured-dedicated-6059.html
- http://www.securityfocus.com/bid/61116
- https://www.mavitunasecurity.com/xss-and-sql-injection-vulnerabilities-in-minibb/
- http://osvdb.org/95122
- http://seclists.org/fulldisclosure/2013/Jul/102
- http://www.minibb.com/download.php?file=minibb_update
- http://www.minibb.com/forums/news-9/minibb-3.0.1-released-stable-fixed-secured-dedicated-6059.html
- http://www.securityfocus.com/bid/61116
- https://www.mavitunasecurity.com/xss-and-sql-injection-vulnerabilities-in-minibb/
CWEs
CWE-79
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.