CVE-2006-0364
Mybulletinboard - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in MyBulletinBoard (MyBB) allows remote attackers to inject arbitrary web script or HTML via a signature containing a JavaScript URI in the SRC attribute of an IMG element, in which the URI uses SGML numeric character references without trailing semicolons, as demonstrated by "javascript".
References (6)
Scores
EPSS
0.0067
EPSS Percentile
71.1%
Classification
CWE
CWE-79
Status
draft
Affected Products (7)
mybulletinboard/mybulletinboard
mybulletinboard/mybulletinboard
mybulletinboard/mybulletinboard
mybulletinboard/mybulletinboard
mybulletinboard/mybulletinboard
mybulletinboard/mybulletinboard
mybulletinboard/mybulletinboard
Timeline
Published
Jan 22, 2006
Tracked Since
Feb 18, 2026