FluxBB Multiple Security Vulnerabilities

FluxBB is prone to a cross-site scripting vulnerability, a cross-site request-forgery vulnerability and an URI-redirection vulnerability.

An attacker may exploit these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, perform unauthorized actions, conduct phishing attacks and disclose or modify sensitive information. Other attacks may also be possible.

FluxBB 1.5.3 is vulnerable; other versions may also be affected.


 

Privacy Statement
Copyright 2010, SecurityFocus