Matt Posted July 12, 2013 Report Posted July 12, 2013 Description : MintBoard version 0.3 suffers from cross site scripting vulnerabilitiesAuthor : Canberk BOLATSource : MintBoard 0.3 Cross Site Scripting ? Packet StormCode : Information--------------------Name : XSS Vulnerabilities in MintBoardSoftware : MintBoard 0.3 and possibly below.Vendor Homepage : http://www.mintboard.comVulnerability Type : Cross-Site ScriptingSeverity : MediumResearcher : Canberk BolatAdvisory Reference : NS-13-001Description--------------------Mintboard is a forum software who aims to do less and do it better. Anattempt to say goodbye to the bloat found in forum software.Details--------------------MintBoard is affected by XSS vulnerabilities in version 0.3.http://example.com/?login=3 (POST: name)http://example.com/?login=3 (POST: pass)http://example.com/?signup=3 (POST: name)http://example.com/?signup=3 (POST: pass)You can read the full article about Cross-Site Scripting and SQL Injectionvulnerabilities from here:Cross-site Scripting (XSS):https://www.mavitunasecurity.com/xss-vulnerabilities-in-mintboard/Solution---------------------Advisory Timeline--------------------06/12/2012 - First contact10/07/2013 - Advisory ReleasedCredits--------------------It has been discovered on testing of Netsparker, Web Application SecurityScanner.References--------------------Vendor Url / Patch :MSL Advisory Link :https://www.mavitunasecurity.com/xss-vulnerabilities-in-mintboard/Netsparker Advisories :https://www.mavitunasecurity.com/netsparker-advisories/About Netsparker--------------------Netsparker® can find and report security issues such as SQL Injection andCross-site Scripting (XSS) in all web applications regardless of theplatform and the technology they are built on. Netsparker's uniquedetection and exploitation techniques allows it to be dead accurate inreporting hence it's the first and the only False Positive Free webapplication security scanner.-- Netsparker Advisories, <advisories@mavitunasecurity.com>Homepage, http://www.mavitunasecurity.com/netsparker-advisories/ Quote