VID |
21916 |
Severity |
30 |
Port |
80, ... |
Protocol |
TCP |
Class |
CGI |
Detailed Description |
A version of Ideal BB is older than 1.5.3 has been installed on the host. Ideal BB is a bulletin board program for Microsoft Windows platforms. Ideal BB versions prior to 1.5.3 are vulnerable to multiple vulnerabilities, which could be exploited by a remote attacker to conduct SQL injection, cross-site scripting and HTTP response splitting vulnerabilities.
* Note: This check solely relied on the version number of Ideal BB on the remote Web server to assess this vulnerability, so this might be a false positive.
* References: http://www.securitytracker.com/alerts/2004/Oct/1011691.html http://secunia.com/advisories/12835/
* Platforms Affected: Ideal Science, Inc., Ideal BB versions prior to 1.5.3 Microsoft Windows Any version |
Recommendation |
Upgrade to the latest version of Ideal BB (1.5.3 or later), available from the Ideal Science Download Web site at http://www.idealscience.com |
Related URL |
CVE-2004-2207,CVE-2004-2208,CVE-2004-2209 (CVE) |
Related URL |
11424 (SecurityFocus) |
Related URL |
17727 (ISS) |
|