Board-TNK Web Information Cross-Agent Scripting Vulnerability

Linux-Sottises Board-TNK is a PHP based discussion board. Originally developed for Linux, it may run on any platform supporting PHP and MySQL. A cross-agent scripting vulnerability has been reported in some versions of Board-TNK. User supplied input is not properly escaped when displayed as the Web information of a post, allowing inclusion of arbitrary script code.


 

Privacy Statement
Copyright 2010, SecurityFocus