MyBB DevBB 1.0 install.php Reconfiguration Vulnerability
BID:4723
Info
MyBB DevBB 1.0 install.php Reconfiguration Vulnerability
| Bugtraq ID: | 4723 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 11 2002 12:00AM |
| Updated: | May 11 2002 12:00AM |
| Credit: | Posted to BugTraq on May 11, 2002 by frog frog <[email protected]> |
| Vulnerable: |
MyBB DevBB 1.0 |
| Not Vulnerable: | |
Discussion
MyBB DevBB 1.0 install.php Reconfiguration Vulnerability
MyBB DevBB 1.0 is a php based web discussion forum. An installation script (install.php) may be left in an accessible location after the installation process is completed. This script can be used to obtain administrative access by modifying the package's configuration.
MyBB DevBB 1.0 is a php based web discussion forum. An installation script (install.php) may be left in an accessible location after the installation process is completed. This script can be used to obtain administrative access by modifying the package's configuration.
Exploit / POC
MyBB DevBB 1.0 install.php Reconfiguration Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
MyBB DevBB 1.0 install.php Reconfiguration Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.