Description
Cross-site scripting (XSS) vulnerability in admin/modules/user/users.php in MyBB (aka MyBulletinBoard) 1.6.6 allows remote attackers to inject arbitrary web script or HTML via the conditions[usergroup][] parameter in a search action to admin/index.php.
Remediation
References
Related Vulnerabilities
WordPress Plugin Realty by BestWebSoft Cross-Site Scripting (1.0.9)
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-5625)
WordPress Plugin EZ Google Analytics Cross-Site Scripting (4.1.06)
MediaWiki Other Vulnerability (CVE-2007-0177)
WordPress Plugin Spam protection, AntiSpam, FireWall by CleanTalk Cross-Site Scripting (5.21)