MyBB Prior to 1.4.2 Multiple Security Vulnerabilities
BID:31295
Info
MyBB Prior to 1.4.2 Multiple Security Vulnerabilities
| Bugtraq ID: | 31295 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 22 2008 12:00AM |
| Updated: | Sep 23 2008 02:49PM |
| Credit: | Discovery of these issues is credited to Gulftech, Kellanved, and NeoThermic. |
| Vulnerable: |
MyBulletinBoard MyBulletinBoard 1.4.1 MyBulletinBoard MyBulletinBoard 1.4 MyBulletinBoard MyBulletinBoard 1.2.13 MyBulletinBoard MyBulletinBoard 1.2.12 MyBulletinBoard MyBulletinBoard 1.2.11 MyBulletinBoard MyBulletinBoard 1.2.10 MyBulletinBoard MyBulletinBoard 1.2.5 MyBulletinBoard MyBulletinBoard 1.2.3 MyBulletinBoard MyBulletinBoard 1.1.8 MyBulletinBoard MyBulletinBoard 1.1.7 MyBulletinBoard MyBulletinBoard 1.1.7 MyBulletinBoard MyBulletinBoard 1.1.6 MyBulletinBoard MyBulletinBoard 1.1.5 MyBulletinBoard MyBulletinBoard 1.1.4 MyBulletinBoard MyBulletinBoard 1.1.3 MyBulletinBoard MyBulletinBoard 1.1.2 MyBulletinBoard MyBulletinBoard 1.1.2 MyBulletinBoard MyBulletinBoard 1.1.1 MyBulletinBoard MyBulletinBoard 1.1 MyBulletinBoard MyBulletinBoard 1.0.4 MyBulletinBoard MyBulletinBoard 1.0.3 MyBulletinBoard MyBulletinBoard 1.0.2 MyBulletinBoard MyBulletinBoard 1.0.1 MyBulletinBoard MyBulletinBoard 1.0 PR2 MyBulletinBoard MyBulletinBoard 1.0 MyBulletinBoard MyBulletinBoard RC4 MyBulletinBoard MyBulletinBoard RC3 MyBulletinBoard MyBulletinBoard RC2 MyBulletinBoard MyBulletinBoard RC1 MyBulletinBoard MyBulletinBoard 1.2 MyBulletinBoard MyBulletinBoard 1.10 |
| Not Vulnerable: |
MyBulletinBoard MyBulletinBoard 1.4.2 |
Discussion
MyBB Prior to 1.4.2 Multiple Security Vulnerabilities
MyBB is prone to multiple security vulnerabilities, including a cross-site scripting issue and multiple unspecified issues.
Very few details are available regarding these issues. We will update this BID as more information emerges.
An attacker may leverage the cross-site scripting issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to MyBB 1.4.2 are vulnerable.
MyBB is prone to multiple security vulnerabilities, including a cross-site scripting issue and multiple unspecified issues.
Very few details are available regarding these issues. We will update this BID as more information emerges.
An attacker may leverage the cross-site scripting issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to MyBB 1.4.2 are vulnerable.
Exploit / POC
MyBB Prior to 1.4.2 Multiple Security Vulnerabilities
Attackers can exploit the cross-site scripting issue by enticing an unsuspecting to victim to follow a malicious URI. Attackers may likely exploit the other issues via a browser.
Attackers can exploit the cross-site scripting issue by enticing an unsuspecting to victim to follow a malicious URI. Attackers may likely exploit the other issues via a browser.
Solution / Fix
MyBB Prior to 1.4.2 Multiple Security Vulnerabilities
Solution:
The vendor has released an update. Please see the references for more information.
Solution:
The vendor has released an update. Please see the references for more information.
References
MyBB Prior to 1.4.2 Multiple Security Vulnerabilities
References:
References:
- MyBB 1.4.2 Released - Maintenance and Security Update (MyBB)
- MyBulletinBoard Homepage (MyBulletinBoard)