CVE-2019-6979
MEDIUMIP_History_Logs 1.0.2 - Cross-Site Scripting via User-Agent Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-6979. PoCs published by 0xB9.
AI-analyzed exploit summary This is a writeup describing a stored XSS vulnerability in the MyBB IP History Logs Plugin 1.0.2. The exploit involves injecting malicious JavaScript via the User-Agent header, which executes when an admin views the IP history logs.
Description
An issue was discovered in the User IP History Logs (aka IP_History_Logs) plugin 1.0.2 for MyBB. There is XSS via the admin/modules/tools/ip_history_logs.php useragent field.
Exploits (1)
This is a writeup describing a stored XSS vulnerability in the MyBB IP History Logs Plugin 1.0.2. The exploit involves injecting malicious JavaScript via the User-Agent header, which executes when an admin views the IP history logs.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N