S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 6, 2024

CVE-2004-1965 Scanner

CVE-2004-1965 scanner - Open Redirect vulnerability in Open Bulletin Board (OpenBB)

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.7k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2004-1965
4.3
CVSS

Multiple cross-site scripting (XSS) vulnerabilities in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) redirect parameter to member.php, (2) to parameter to myhome.php (3) TID parameter to post.php, or (4) redirect parameter to index.php.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Open Bulletin Board (OpenBB) is an online forum software used for the purpose of facilitating discussions and information sharing among groups of individuals. With an easy-to-use interface, it allows users to create topics, post messages, and participate in discussions with other members of the forum. OpenBB has been widely adopted and used in various online communities.

However, OpenBB has been found to contain multiple cross-site scripting (XSS) vulnerabilities, such as CVE-2004-1965. This vulnerability allows remote attackers to inject arbitrary web script or HTML via various parameters, such as the redirect parameter to member.php, to parameter to myhome.php, TID parameter to post.php, or redirect parameter to index.php. This could lead to attackers exploiting this vulnerability to steal sensitive information or trick users into submitting personal data.

If this vulnerability is exploited, it can cause serious harm to system security, as attackers could take over the forum administration panel, delete or modify posts, or even delete the entire forum. The vulnerability can be further exploited to steal sensitive data such as user credentials, causing damage to users' online reputation. Thus, it is critical to take measures to prevent this vulnerability from being exploited.

S4E is a security platform that provides advanced tools to help businesses easily assess and identify vulnerabilities in their digital assets. With our advanced features, you can analyze web applications, network infrastructure, mobile applications, databases, operating systems, and more, to detect vulnerabilities and proactively mitigate risks. By signing up for our platform, you can keep your digital assets and sensitive data secure from malicious attackers.

 

REFERENCES

Solution Advice

To protect against this vulnerability, forum administrators can take the following precautions:

  • Install the latest patches or updates released by OpenBB to avoid this vulnerability.
  • Use a firewall to restrict network traffic to the OpenBB server.
  • Enforce secure coding practices to prevent XSS and other web security threats.
  • Deploy Intrusion detection/prevention systems (IDS/IPS) to detect and prevent attacks.
  • Conduct vulnerability assessments and penetration testing to identify and fix vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2004-1965 scanner - Open Redirect vulnerability in Open Bulletin Board (OpenBB) | S4E