VYPR
Unrated severityNVD Advisory· Published Jun 2, 2009· Updated Apr 23, 2026

CVE-2009-1881

CVE-2009-1881

Description

Cross-site scripting (XSS) vulnerability in MT312 IMG-BBS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to model.php with a timestamp before 20090521.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cross-site scripting in MT312 IMG-BBS allows remote attackers to inject arbitrary web script via model.php with a timestamp before 2009-05-21.

Vulnerability

IMG-BBS from MT312, a web log system for posting pictures via email from mobile phones, contains a cross-site scripting (XSS) vulnerability in model.php. Versions of IMG-BBS (imgbbs.lzh) that contain model.php with a timestamp prior to May 21, 2009 are affected [1][2]. The vulnerability allows injection of arbitrary web script or HTML via unspecified vectors [1].

Exploitation

An attacker can exploit this vulnerability by crafting a malicious URL or input that, when processed by the vulnerable model.php, injects script code. The attack requires no authentication and can be delivered over the network, but the user must interact with the crafted link or content [2]. The exact attack vector is not detailed in the references, but typical XSS exploitation involves tricking a user into clicking a specially crafted link.

Impact

Successful exploitation allows an attacker to execute arbitrary script in the user's web browser within the context of the vulnerable site [1][2]. This can lead to information disclosure, session hijacking, or other client-side attacks. The CVSS v2 base score is 4.3 (Medium) with partial integrity impact and no confidentiality or availability impact [2].

Mitigation

The vendor, MT312, has released an updated version of IMG-BBS (imgbbs.lzh) that fixes the vulnerability. Users should update to the latest version [1][2]. No workarounds are mentioned in the references. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog.

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.