XMB Forum 1.6 pre-beta - Image Tag Script Injection
Author: skizzik
type: webapps
platform: php
port:
date_added: 2002-02-22
date_updated: 2012-09-12
verified: 1
codes: CVE-2002-0316;OSVDB-8874
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/4167/info
The Extreme Message Board (XMB) 1.6 Magic Lantern pre-beta version reportedly allows JavaScript and HTML to be entered in messages. This can be achieved by entering script or HTML between [img] and [/img] tags in a forum message.
This has been fixed in the 1.6 Magic Lantern final beta version of XMB.
[img]javasCript:alert('Hello world.')[/img]