Description
An issue was discovered in inc/class_feedgeneration.php in MyBB 1.8.17. On the forum RSS Syndication page, one can generate a URL such as http://localhost/syndication.php?fid=&type=atom1.0&limit=15. The thread titles (within title elements of the generated XML documents) aren't sanitized, leading to XSS.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2006-1874 Vulnerability (CVE-2006-1874)
WordPress Plugin WP Customer Reviews Unspecified Vulnerability (3.0.7)
WordPress Plugin File Browser, Manager, Backup (+ Database) Security Bypass (1.23)
WordPress Plugin ZoomSounds-WordPress Wave Audio Player with Playlist Directory Traversal (6.45)