J-Security Center

Title: MercuryBoard Multiple Input Validation Vulnerabilities

Severity: MODERATE

Description:

MercuryBoard is a typical Web based message board application designed in PHP with an SQL database back end. It is freely available for all platforms that support PHP.

Multiple input validation vulnerabilities affect MercuryBoard. These issues are due to a failure of the application to properly sanitize user-supplied input prior to using it in critical functionality.

Multiple cross-site scripting issues affect MercuryBoard. These issues affect the 'l', 's', 't', 'to', and 're' parameters of the 'index.php' script.

An SQL injection vulnerability affects MercuryBoard as well. This issue affects the 't' parameter of the 'index.php' script.

An attacker may leverage these issues to execute arbitrary code in the browser of an unsuspecting user and manipulate SQL queries against the underlying database. This may facilitate the theft of authentication credentials, destruction of data, and other attacks.

Affected Products:

  • MercuryBoard Message Board 1.1.0
  • MercuryBoard Message Board 1.1.1

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.