MyBB Multiple Vulnerabilities
BID:36463
Info
MyBB Multiple Vulnerabilities
| Bugtraq ID: | 36463 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 21 2009 12:00AM |
| Updated: | Sep 21 2009 04:50PM |
| Credit: | endeavormac, frostschutz, and TheLinx. |
| Vulnerable: |
MyBB MyBB 1.4.8 MyBB MyBB 1.2 |
| Not Vulnerable: |
MyBB MyBB 1.4.9 |
Discussion
MyBB Multiple Vulnerabilities
MyBB is prone to multiple vulnerabilities because the application fails to sufficiently sanitize user-supplied input.
Exploiting these issues could allow an attacker to carry out SQL-injection attacks and register accounts using existing usernames of other users.
MyBB 1.4.8 and 1.2 are affected; other versions may be vulnerable as well.
MyBB is prone to multiple vulnerabilities because the application fails to sufficiently sanitize user-supplied input.
Exploiting these issues could allow an attacker to carry out SQL-injection attacks and register accounts using existing usernames of other users.
MyBB 1.4.8 and 1.2 are affected; other versions may be vulnerable as well.
Exploit / POC
MyBB Multiple Vulnerabilities
An attacker can exploit these issues via a browser.
An attacker can exploit these issues via a browser.
Solution / Fix
MyBB Multiple Vulnerabilities
Solution:
The vendor has released MyBB 1.4.9 to address these issues. Please see the references for details.
MyBB MyBB 1.2
MyBB MyBB 1.4.8
Solution:
The vendor has released MyBB 1.4.9 to address these issues. Please see the references for details.
MyBB MyBB 1.2
-
MyBB MyBB 1.4.9
http://mybboard.net/download/latest
MyBB MyBB 1.4.8
-
MyBB MyBB 1.4.9
http://mybboard.net/download/latest
References
MyBB Multiple Vulnerabilities
References:
References: