Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.16247
Category:Web application abuses
Title:Multiple Vulnerabilities in MercuryBoard
Summary:The remote host is running MercuryBoard, a message board system written inPHP.;; Multiple vulnerabilities have been discovered in the product that allow an attacker to cause numerous cross site; scripting attacks, inject arbitrary SQL statements and disclose the path under which the product has been; installed.
Description:Summary:
The remote host is running MercuryBoard, a message board system written inPHP.

Multiple vulnerabilities have been discovered in the product that allow an attacker to cause numerous cross site
scripting attacks, inject arbitrary SQL statements and disclose the path under which the product has been
installed.

Solution:
Upgrade to MercuryBoard version 1.1.3.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2005-0306
BugTraq ID: 12359
http://www.securityfocus.com/bid/12359
Bugtraq: 20050124 Multiple vulnerabilities in MercuryBoard 1.1.1 (Google Search)
http://marc.info/?l=bugtraq&m=110661795632354&w=2
XForce ISS Database: mercuryboard-multiple-script-path-disclosure(19048)
https://exchange.xforce.ibmcloud.com/vulnerabilities/19048
Common Vulnerability Exposure (CVE) ID: CVE-2005-0307
XForce ISS Database: mercuryboard-multiple-scripts-xss(19050)
https://exchange.xforce.ibmcloud.com/vulnerabilities/19050
Common Vulnerability Exposure (CVE) ID: CVE-2005-0414
Bugtraq: 20050209 Mercuryboard =?iso-8859-1?Q?<=3D?= 1.1.1 Working Sql Injection (Google Search)
http://marc.info/?l=bugtraq&m=110797495532358&w=2
http://securitytracker.com/id?1013137
XForce ISS Database: mercuryboard-index-sql-injection(19051)
https://exchange.xforce.ibmcloud.com/vulnerabilities/19051
Common Vulnerability Exposure (CVE) ID: CVE-2005-0460
http://lostmon.blogspot.com/2005/02/mercuryboard-debug-information.html
http://www.osvdb.org/13787
http://secunia.com/advisories/14284
Common Vulnerability Exposure (CVE) ID: CVE-2005-0462
http://lostmon.blogspot.com/2005/02/mercuryboard-forumphp-f-variable-xss.html
http://secunia.com/advisories/13937
Common Vulnerability Exposure (CVE) ID: CVE-2005-0662
http://www.osvdb.org/14308
http://secunia.com/advisories/14414
Common Vulnerability Exposure (CVE) ID: CVE-2005-0663
Common Vulnerability Exposure (CVE) ID: CVE-2005-0878
BugTraq ID: 12872
http://www.securityfocus.com/bid/12872
http://secunia.com/advisories/14679
XForce ISS Database: mercuryboard-title-pm-xss(19797)
https://exchange.xforce.ibmcloud.com/vulnerabilities/19797
CopyrightCopyright (C) 2005 Noam Rathaus

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.