MyBB Multiple Cross Site Scripting Vulnerabilities
BID:35504
Info
MyBB Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 35504 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 26 2009 12:00AM |
| Updated: | Jun 26 2009 02:19PM |
| Credit: | frostschutz |
| Vulnerable: |
MyBB MyBB 1.4.7 MyBB MyBB 1.4.6 MyBB MyBB 1.4.5 MyBB MyBB 1.4.3 MyBB MyBB 1.4.2 |
| Not Vulnerable: |
MyBB MyBB 1.4.8 |
Discussion
MyBB Multiple Cross Site Scripting Vulnerabilities
MyBB is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to MyBB 1.4.8 are vulnerable.
MyBB is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Versions prior to MyBB 1.4.8 are vulnerable.
Exploit / POC
MyBB Multiple Cross Site Scripting Vulnerabilities
To exploit these issues, an attacker must entice an unsuspecting victim into following a malicious URI.
To exploit these issues, an attacker must entice an unsuspecting victim into following a malicious URI.
Solution / Fix
MyBB Multiple Cross Site Scripting Vulnerabilities
Solution:
The vendor has released an update. Please see the references for details.
MyBB MyBB 1.4.7
Solution:
The vendor has released an update. Please see the references for details.
MyBB MyBB 1.4.7
-
MyBB mybb_1407_patches.txt
http://mybboard.net/download/105
References
MyBB Multiple Cross Site Scripting Vulnerabilities
References:
References: