MyBB Compromised Source Packages Backdoor Vulnerability
BID:49993
Info
MyBB Compromised Source Packages Backdoor Vulnerability
| Bugtraq ID: | 49993 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 06 2011 12:00AM |
| Updated: | Oct 10 2011 11:30AM |
| Credit: | Reported by the vendor |
| Vulnerable: |
MyBB MyBB 1.6.4 |
| Not Vulnerable: | |
Discussion
MyBB Compromised Source Packages Backdoor Vulnerability
MyBB is prone to a backdoor vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the application. Successful attacks will compromise the affected application.
MyBB versions 1.6.4 prior to October 6th, 2011 are vulnerable.
MyBB is prone to a backdoor vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the application. Successful attacks will compromise the affected application.
MyBB versions 1.6.4 prior to October 6th, 2011 are vulnerable.
Exploit / POC
MyBB Compromised Source Packages Backdoor Vulnerability
An attacker can use readily available tools to exploit this issue.
The following exploit is available:
An attacker can use readily available tools to exploit this issue.
The following exploit is available:
Solution / Fix
MyBB Compromised Source Packages Backdoor Vulnerability
Solution:
The vendor released an update. Please see the references for details.
Solution:
The vendor released an update. Please see the references for details.
References
MyBB Compromised Source Packages Backdoor Vulnerability
References:
References:
- 1.6.4 Security Vulnerability (MyBB)
- MyBB Homepage (MyBB)
- This patch file fixes security issues with 1.6.4 (MyBB)