info
discussion
exploit
solution
references
MyBB Multiple HTML Injection Vulnerabilities
Attackers can exploit these issues via a web client or specially crafted avatar images.
A sample exploit has been provided:
/data/vulnerabilities/exploits/mybb-avatar-html-inj.js
Privacy Statement
Copyright 2010, SecurityFocus