Korean
<< Back
VID 21625
Severity 30
Port 80, ...
Protocol TCP
Class CGI
Detailed Description A version of MercuryBoard which is older than version 1.1.3 is detected as installed on the host. MercuryBoard is a message board system written in PHP. MercuryBoard versions prior to 1.1.3 are vulnerable to multiple input validation vulnerabilities, which can be exploited by remote attackers to conduct cross-site scripting and SQL injection attacks.

1) Multiple SQL injection vulnerabilities can be exploited to manipulate SQL queries by injecting arbitrary SQL code.
2) Multiple cross-site scripting vulnerabilities can be exploited to execute arbitrary HTML and script code in a user's browser session in context of a vulnerable site.

* Note: This check solely relied on the version number of the MercuryBoard installed on the remote Web server to assess this vulnerability, so this might be a false positive.

* References:
http://www.osvdb.org/displayvuln.php?osvdb_id=13262
http://www.osvdb.org/displayvuln.php?osvdb_id=13263
http://www.osvdb.org/displayvuln.php?osvdb_id=13264
http://www.osvdb.org/displayvuln.php?osvdb_id=13265
http://www.osvdb.org/displayvuln.php?osvdb_id=13266
http://www.osvdb.org/displayvuln.php?osvdb_id=13267
http://www.osvdb.org/displayvuln.php?osvdb_id=13764
http://www.osvdb.org/displayvuln.php?osvdb_id=13787
http://www.osvdb.org/displayvuln.php?osvdb_id=14307
http://www.osvdb.org/displayvuln.php?osvdb_id=14308
http://secunia.com/advisories/13937
http://secunia.com/advisories/14284
http://lostmon.blogspot.com/2005/02/mercuryboard-debug-information.html
http://lostmon.blogspot.com/2005/02/mercuryboard-forumphp-f-variable-xss.html

* Platforms Affected:
MercuryBoard versions prior to 1.1.3
Any operating system Any version
Recommendation Upgrade to the latest version of MercuryBoard (1.1.3 or later), available from the MercuryBoard Web site at http://www.mercuryboard.com/
Related URL CVE-2005-0306,CVE-2005-0307,CVE-2005-0414,CVE-2005-0460,CVE-2005-0462 (CVE)
Related URL 12359,12503,12578,12706,12707 (SecurityFocus)
Related URL (ISS)