MyBB Template Parser Remote PHP Code Execution Vulnerability
BID:38766
Info
MyBB Template Parser Remote PHP Code Execution Vulnerability
| Bugtraq ID: | 38766 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 16 2010 12:00AM |
| Updated: | Mar 16 2010 12:00AM |
| Credit: | flyh4t |
| Vulnerable: |
MyBulletinBoard MyBulletinBoard 1.4.11 |
| Not Vulnerable: | |
Discussion
MyBB Template Parser Remote PHP Code Execution Vulnerability
MyBB (MyBulletinBoard) is prone to a remote PHP code-execution vulnerability.
An attacker can exploit this issue to inject and execute arbitrary malicious PHP code in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
MyBB 1.4.11 is vulnerable; other versions may also be affected.
MyBB (MyBulletinBoard) is prone to a remote PHP code-execution vulnerability.
An attacker can exploit this issue to inject and execute arbitrary malicious PHP code in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
MyBB 1.4.11 is vulnerable; other versions may also be affected.
Exploit / POC
MyBB Template Parser Remote PHP Code Execution Vulnerability
Attackers can exploit this issue by enticing an unsuspecting victim to install a malicious template.
Attackers can exploit this issue by enticing an unsuspecting victim to install a malicious template.
References
MyBB Template Parser Remote PHP Code Execution Vulnerability
References:
References:
- MyBB 1.4 admin remote code execution vulnerability (flyh4t)
- MyBB Homepage (MyBB)